SUSPICIOUS — laguxek_pugefewemil.pdf
SUSPICIOUS — laguxek_pugefewemil.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
0273e4379a9db12b2594d5a590fa547907ff068606fb5f268f9367b3c7ecfa05 - SHA-1:
bb8cdfd055497a6f2ea02c3a86a7ba4d52ca36d2 - MD5:
7184a461251099a8b811cabdfbff5d2a - ssdeep:
1536:FGFupr31pTA3sIv/IIBb+SZb36EaWh2hyPm:YFupL1gvg2b+SoE+l - TLSH:
T1F8349EF350A3DD4CBBCB9F43A9EA0099658AD68D6176D7A0458C372CC47C2ED6F10990 - Submitted as: laguxek_pugefewemil.pdf
- File type: pdf · Size: 56236 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=palabras%20tipicas%20de%20guatemala, https://uploads.strikinglycdn.com/files/c0b26801-12cd-43b9-bfd4-9b6aaaf66af0/gavolonewa.pdf, https://uploads.strikinglycdn.com/files/93e930bf-756a-49ef-818a-44ee0ae9ab8e/63104735841.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=palabras%20tipicas%20de%20guatemala
- https://uploads.strikinglycdn.com/files/c0b26801-12cd-43b9-bfd4-9b6aaaf66af0/gavolonewa.pdf
- https://uploads.strikinglycdn.com/files/93e930bf-756a-49ef-818a-44ee0ae9ab8e/63104735841.pdf
- https://uploads.strikinglycdn.com/files/4c6f74e0-d598-44bf-87b5-7d3e4a8a2669/vuzezok.pdf
- https://site-1040244.mozfiles.com/files/1040244/nozonawuzizelekiranoj.pdf
- https://site-1044503.mozfiles.com/files/1044503/nugadeweruvedivi.pdf
- https://site-1039694.mozfiles.com/files/1039694/dunewejikaxawunukebu.pdf
- https://site-1038337.mozfiles.com/files/1038337/46172058183.pdf
- https://site-1044303.mozfiles.com/files/1044303/13259716893.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f871d68a6b67.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f86fbbc85d79.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f86f534261d8.pdf
- https://cdn.shopify.com/s/files/1/0430/3526/3130/files/89005834905.pdf
- https://cdn.shopify.com/s/files/1/0428/3518/1734/files/how_many_straight_edges_does_a_rectangular_prism_have.pdf
- https://cdn.shopify.com/s/files/1/0488/1098/3589/files/widufugevutuzixa.pdf
- https://cdn.shopify.com/s/files/1/0504/1573/0886/files/jefebudadesifixodaduxedef.pdf
- https://cdn.shopify.com/s/files/1/0434/2464/5272/files/okavango_delta_google_maps.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f872a61225bc.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f87173ac1263.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f8712739ba95.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f872a8d66184.pdf
- https://uploads.strikinglycdn.com/files/f29df739-d44c-468e-8bd8-604ba8390957/67798376198.pdf
- https://uploads.strikinglycdn.com/files/53fa2da0-7d03-4a2a-89fb-4c9eba90aa2e/wafufajotibatipasotidoj.pdf
- https://uploads.strikinglycdn.com/files/86ec4703-79e5-484c-aceb-bec5f4301bc3/latokibovigadapubaw.pdf
- https://uploads.strikinglycdn.com/files/c4fb91df-eba6-4ae2-aad1-15a652decc03/binepapowe.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1040244.mozfiles.com
- site-1044503.mozfiles.com
- site-1039694.mozfiles.com
- site-1038337.mozfiles.com
- site-1044303.mozfiles.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report