SUSPICIOUS — lalatim.pdf
SUSPICIOUS — lalatim.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
03256d29cc50e760490ed33103b9f5c443c120f1d29fcc4e9ffcd47266acb5f2 - SHA-1:
7a272a5d55b4e27b2cc10e5e1341cb739b71705f - MD5:
b6032d2756abd7cdfa37bec13f2a55f3 - ssdeep:
768:TgGzpDfp8hk9+ke9yXq588fp2aRfBBx2sHA3Ez2FesrlcC4svJnkTPGVOa:sGFLpMke9ywnNpVgXPrl7reTPGVOa - TLSH:
T160339DF344A3EC9C768BAF079EEB109D6189D389606B979048CC271DD07C7BD6E40650 - Submitted as: lalatim.pdf
- File type: pdf · Size: 52312 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=skyrim%20dawnstar%20khajiit%20caravan, https://uploads.strikinglycdn.com/files/f03fdc19-9807-45eb-848a-57eb377f1bbb/bovivivamirukuwopeguketo.pdf, https://uploads.strikinglycdn.com/files/56204aef-f27e-4b0e-b01f-4fc5a0a3b31f/17602252687.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=skyrim%20dawnstar%20khajiit%20caravan
- https://uploads.strikinglycdn.com/files/f03fdc19-9807-45eb-848a-57eb377f1bbb/bovivivamirukuwopeguketo.pdf
- https://uploads.strikinglycdn.com/files/56204aef-f27e-4b0e-b01f-4fc5a0a3b31f/17602252687.pdf
- https://uploads.strikinglycdn.com/files/547a9d68-40d6-4cb6-9afa-1c92918e5d32/69162766944.pdf
- https://uploads.strikinglycdn.com/files/0c5183f4-dc1e-4e42-9f2b-eaf514e08954/62584377615.pdf
- https://uploads.strikinglycdn.com/files/44af929b-011a-4008-abed-603e34b9e538/liwekaged.pdf
- https://uploads.strikinglycdn.com/files/cc7e580e-3f8f-4770-8042-27adafa7a23b/10266586057.pdf
- https://uploads.strikinglycdn.com/files/3896c629-ff55-4c55-bc66-cea23808abcf/somumalanerevebatikupif.pdf
- https://uploads.strikinglycdn.com/files/b149ce28-e426-425c-8b7a-7057ac8885db/razigenirefo.pdf
- https://uploads.strikinglycdn.com/files/697c2bd0-2810-4747-bb05-5851b9fb1132/ruwusir.pdf
- https://uploads.strikinglycdn.com/files/045a1d7a-78f6-470e-a75d-cbf2172a38e9/24484003980.pdf
- https://site-1036652.mozfiles.com/files/1036652/70821019888.pdf
- https://site-1042917.mozfiles.com/files/1042917/39923565158.pdf
- https://site-1039749.mozfiles.com/files/1039749/32191420942.pdf
- https://site-1044115.mozfiles.com/files/1044115/12370568237.pdf
- https://site-1036884.mozfiles.com/files/1036884/xedawupazixaropo.pdf
- https://cdn.shopify.com/s/files/1/0492/3339/5868/files/verizon_channel_guide_2015.pdf
- https://cdn.shopify.com/s/files/1/0433/7739/3815/files/split_end_trimmer_reviews.pdf
- https://cdn.shopify.com/s/files/1/0480/6308/6756/files/61368248055.pdf
- https://cdn.shopify.com/s/files/1/0491/7896/8230/files/new_getter_robo.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xereromejiv-koxozirusoror-moxonujis.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/c2099e721b.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/gosibokuvefuj.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/2919036.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/baputedev.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036652.mozfiles.com
- site-1042917.mozfiles.com
- site-1039749.mozfiles.com
- site-1044115.mozfiles.com
- site-1036884.mozfiles.com
- cdn.shopify.com
- dutitujazekap.weebly.com
- narogigadi.weebly.com
- keniwuki.weebly.com
- riwisasivituw.weebly.com
- bedizegoresupa.weebly.com
- ridolagu.weebly.com
- gimejexoxixaza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report