SUSPICIOUS — luvafeji.pdf
SUSPICIOUS — luvafeji.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
0f742117794349b6c8ed8554ba28bdbe205bf5c2b774257dfd41bbc1930618d0 - SHA-1:
40eb0c44f0087857ce7dbad8c4a79cd66dcea9d8 - MD5:
ba98d52be9da061d2e9d8691a201ebf1 - ssdeep:
768:GgGzpD8exCBrEJHH9YVlvNJiAv2D91cjTtFNUJp945j6HA8nlbhnkwaEgfR25R0:TGFAekmmlFJiypF7Fl8nl12fY5R0 - TLSH:
T1BD349EF310A7DD8C3A8AAB536EEB2558418ED788A132DB60418C772DC47C77E7E10A51 - Submitted as: luvafeji.pdf
- File type: pdf · Size: 54049 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=robert%20jordan%20wheel%20of%20time%20pdf, https://cdn-cms.f-static.net/uploads/4369632/normal_5f88d51fdb633.pdf, https://cdn-cms.f-static.net/uploads/4365998/normal_5f87171ed94f9.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=robert%20jordan%20wheel%20of%20time%20pdf
- https://cdn-cms.f-static.net/uploads/4369632/normal_5f88d51fdb633.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f87171ed94f9.pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f870d9f92101.pdf
- https://cdn-cms.f-static.net/uploads/4367017/normal_5f885d936c564.pdf
- https://cdn-cms.f-static.net/uploads/4373755/normal_5f8923136dd00.pdf
- https://uploads.strikinglycdn.com/files/0e0f04f4-cfde-460e-9d1c-1c983afecfe4/kikomupuvozadujipuma.pdf
- https://uploads.strikinglycdn.com/files/87081854-ccde-477c-90b7-bd194cc72fe1/fofesoge.pdf
- https://uploads.strikinglycdn.com/files/e98744a1-530c-42ec-8506-74d13b65caeb/todotedam.pdf
- https://uploads.strikinglycdn.com/files/47ceb8ac-f76b-496f-8064-b393bb783cca/fuxar.pdf
- https://uploads.strikinglycdn.com/files/d44aad38-33c2-41f6-accd-ad4899fbe9f6/vikibexosimopinimo.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/3cb113af6.pdf
- https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/lutadotutaku.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/4918653.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/469164fb2021c10.pdf
- https://uploads.strikinglycdn.com/files/6e701aa6-304c-459c-8ddc-0c9a07dbb451/moravomekerumi.pdf
- https://uploads.strikinglycdn.com/files/9525fb27-d812-44a8-a2c4-c64bab9a0548/36263921409.pdf
- https://uploads.strikinglycdn.com/files/327e3381-409e-4f5a-86e6-4d00f606b255/walesezowafim.pdf
- https://uploads.strikinglycdn.com/files/b4d94e0b-e1f1-4613-91f9-9ec644356963/lasikafuzijal.pdf
- https://uploads.strikinglycdn.com/files/78fb172e-b0ea-48ae-9195-cd20cb0f2460/78821755487.pdf
- https://cdn.shopify.com/s/files/1/0502/0667/1026/files/theory_of_self_esteem.pdf
- https://cdn.shopify.com/s/files/1/0482/8794/0776/files/osrs_kings_ransom_training.pdf
- https://cdn.shopify.com/s/files/1/0268/7257/8218/files/es_file_explorer_user_manual_version_3.0.pdf
- https://cdn.shopify.com/s/files/1/0491/8811/0502/files/97802905787.pdf
- https://uploads.strikinglycdn.com/files/4759e072-0660-4278-b0ea-29421f46c035/1268397238.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- keniwuki.weebly.com
- vixijusodu.weebly.com
- jakedekokobara.weebly.com
- dapujevubo.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report