SUSPICIOUS — lomono-zunupigo.pdf
SUSPICIOUS — lomono-zunupigo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
1d760210db215c2ce649a6bf998230b60d050fe54499f535e40f4e10a96c421f - SHA-1:
db14178ec620d6a7f50037766b579b105984dc54 - MD5:
bcc8d72e27580207c05bc2cd7657eb0f - ssdeep:
768:jgGzpD3NNUUuQOxWF+vtYcSIIXHnYSmaA4O0gS6GlEWIPCKAJLM:cGFrZcSv3noaA4O0F6GKwKAJLM - TLSH:
T1F7319EF35097EC5C778B8B07ADFB015A508AE348A137976448DC336CD8BC5ADAE21660 - Submitted as: lomono-zunupigo.pdf
- File type: pdf · Size: 42573 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=rule%20800%20bilge%20pump%20manual, https://cdn.shopify.com/s/files/1/0439/4916/2654/files/boxojokemopij.pdf, https://cdn.shopify.com/s/files/1/0266/7970/5783/files/1301148889.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=rule%20800%20bilge%20pump%20manual
- https://cdn.shopify.com/s/files/1/0439/4916/2654/files/boxojokemopij.pdf
- https://cdn.shopify.com/s/files/1/0266/7970/5783/files/1301148889.pdf
- https://cdn.shopify.com/s/files/1/0429/9587/5989/files/adding_and_subtracting_real_numbers_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0497/0741/7757/files/yoruba_to_english.pdf
- https://cdn.shopify.com/s/files/1/0431/7567/4012/files/fepanutaribebalakakilapi.pdf
- https://cdn.shopify.com/s/files/1/0435/2707/8042/files/taming_of_the_shrew_characters_map.pdf
- https://cdn.shopify.com/s/files/1/0484/9552/6049/files/fortnite_gingerbread_man_mask.pdf
- https://cdn.shopify.com/s/files/1/0433/9286/0327/files/isagenix_coupon_code_january_2020_free_shipping_code.pdf
- https://cdn.shopify.com/s/files/1/0491/8309/6998/files/xugesikosi.pdf
- https://s3.amazonaws.com/sulasatevirexo/75681390323.pdf
- https://s3.amazonaws.com/mejifavo/amri_butterfly_valve_catalogue.pdf
- https://s3.amazonaws.com/vazisi/vixalemedijepa.pdf
- https://s3.amazonaws.com/vukusa/toefl_grammar_practice_worksheets.pdf
- https://uploads.strikinglycdn.com/files/5527425b-2c3b-425a-8947-16dc7d5ba879/xumegunofu.pdf
- https://uploads.strikinglycdn.com/files/2b449069-0f54-462f-b662-8e11f5da044d/zanumururol.pdf
- https://runebipunozup.weebly.com/uploads/1/3/1/4/131406604/tepenu_jumiwisup_jilaba_jupivadonuwob.pdf
- https://rimosuvifakub.weebly.com/uploads/1/3/4/3/134310068/xofifa.pdf
- https://vogemafebin.weebly.com/uploads/1/3/4/2/134235603/zozixe.pdf
- https://fozafilamo.weebly.com/uploads/1/3/4/3/134314768/4970253.pdf
- https://kogatakuzomaw.weebly.com/uploads/1/3/4/4/134444425/027e7f744a.pdf
- https://suganolorifumu.weebly.com/uploads/1/3/0/8/130814011/buxamofezo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- runebipunozup.weebly.com
- rimosuvifakub.weebly.com
- vogemafebin.weebly.com
- fozafilamo.weebly.com
- kogatakuzomaw.weebly.com
- suganolorifumu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report