SUSPICIOUS — lokufesurumib.pdf
SUSPICIOUS — lokufesurumib.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
285d99f68c1dbb2dbe6adac4767e84757c2473f2c9afdcf7035e99f05231d261 - SHA-1:
cae16d274120f1e43f648a8a4ae1244e187e9c85 - MD5:
e6e5d26cfefd29de456d3ea5d8aba685 - ssdeep:
1536:uGFWpu7g52epKHBkELthhwMYjmGuE4pIVlFwjEZ8ZcpMlc2A1:XFWpu7g0ek1twMY6nEnn2j9tlcT - TLSH:
T1FE37D0F344E7EE8CB6879B07ADE21085609AC38DA1379790518C677DC4BC6BE3E50851 - Submitted as: lokufesurumib.pdf
- File type: pdf · Size: 70275 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/7caa86d8-e492-4b61-802d-db3e75cb256d/23082209802.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=galactic%20power%20surge%20stellaris, https://uploads.strikinglycdn.com/files/8b820e65-3737-4f93-9234-fce00a8d799b/duvimeguxigevanumo.pdf, https://uploads.strikinglycdn.com/files/7caa86d8-e492-4b61-802d-db3e75cb256d/23082209802.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=galactic%20power%20surge%20stellaris
- https://uploads.strikinglycdn.com/files/8b820e65-3737-4f93-9234-fce00a8d799b/duvimeguxigevanumo.pdf
- https://uploads.strikinglycdn.com/files/7caa86d8-e492-4b61-802d-db3e75cb256d/23082209802.pdf
- https://uploads.strikinglycdn.com/files/23840fd4-8e3d-4a85-84c4-11766ed0d718/97072093687.pdf
- https://uploads.strikinglycdn.com/files/410cef22-218d-4f1d-8401-3d8c05ade473/40779797541.pdf
- https://uploads.strikinglycdn.com/files/756ac558-d823-4677-b462-99e17550417e/wedojapuzetabulup.pdf
- https://uploads.strikinglycdn.com/files/6347dd45-88b8-4e30-8ecb-2f914cd1e4e7/61142869126.pdf
- https://uploads.strikinglycdn.com/files/ac9a8b0f-9795-4d04-bef9-916cf6149200/14258313379.pdf
- https://uploads.strikinglycdn.com/files/1b47529f-69e9-4bb2-b29e-06845c64ed36/11233291231.pdf
- https://uploads.strikinglycdn.com/files/868eff4e-6b76-47c9-98c9-4f79cd1f33e5/84453533955.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/digokasawuj-jipamuputevuf.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/duwivif.pdf
- https://sukowaletudevux.weebly.com/uploads/1/3/0/8/130874669/5691185.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/letaxum.pdf
- https://site-1043885.mozfiles.com/files/1043885/futakubudizadizixit.pdf
- https://site-1042013.mozfiles.com/files/1042013/iwi_tavor_sar_manual.pdf
- https://site-1042193.mozfiles.com/files/1042193/xatipubarasetiv.pdf
- https://site-1040099.mozfiles.com/files/1040099/79805583793.pdf
- https://site-1043096.mozfiles.com/files/1043096/fonogunawibevupok.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f87266c8aa9a.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f87083e52e10.pdf
- https://cdn-cms.f-static.net/uploads/4374364/normal_5f88e3ed6e971.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f87b2851476a.pdf
- https://site-1041694.mozfiles.com/files/1041694/hansen_solubility_parameters_a_users_handbook.pdf
- https://site-1043667.mozfiles.com/files/1043667/96423573205.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- keniwuki.weebly.com
- genigudepa.weebly.com
- sukowaletudevux.weebly.com
- juragubiv.weebly.com
- site-1043885.mozfiles.com
- site-1042013.mozfiles.com
- site-1042193.mozfiles.com
- site-1040099.mozfiles.com
- site-1043096.mozfiles.com
- cdn-cms.f-static.net
- site-1041694.mozfiles.com
- site-1043667.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report