SUSPICIOUS — lepimebosuxomu_fukixusa_famosulizik_sukoruzikazil.pdf
SUSPICIOUS — lepimebosuxomu_fukixusa_famosulizik_sukoruzikazil.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
32eeabcb3f0d2fbdcb198a8b90d8b27b338bd0e885bed4019c5f76881be262d5 - SHA-1:
6906c8b5f035cff230a1503a39927864b4a5f8db - MD5:
9c62ab76b3e1d9ec8ea84603eafa8ab6 - ssdeep:
768:dgGzpDtpkQfLUYc4NJ92bdzRslaPssa7d1mhAl+rX4Jf:eGFZp4O4PSmhvX4Jf - TLSH:
T15F2F8DF350A7ED8D7A87AB036CE711A96089C38D6137EBA0548C672CD8BC5BD7E10851 - Submitted as: lepimebosuxomu_fukixusa_famosulizik_sukoruzikazil.pdf
- File type: pdf · Size: 35546 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=zawgyi%20ttf%20font, https://uploads.strikinglycdn.com/files/09e36c13-a478-4651-af7d-8995f81c0488/tunax.pdf, https://uploads.strikinglycdn.com/files/4b71ba1f-80c7-433a-ab48-8915f6e85190/82623691453.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=zawgyi%20ttf%20font
- https://uploads.strikinglycdn.com/files/09e36c13-a478-4651-af7d-8995f81c0488/tunax.pdf
- https://uploads.strikinglycdn.com/files/4b71ba1f-80c7-433a-ab48-8915f6e85190/82623691453.pdf
- https://uploads.strikinglycdn.com/files/1116ada8-56be-4649-8064-3a99f5fafb93/89221164116.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f8700e31bd0c.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f870158ef3ac.pdf
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f870dd7cb42c.pdf
- https://cdn.shopify.com/s/files/1/0503/3702/2102/files/tivo_premiere_series_4_manual.pdf
- https://cdn.shopify.com/s/files/1/0430/6488/5397/files/itube_apk_ios_11.pdf
- https://cdn.shopify.com/s/files/1/0434/3421/3538/files/what_are_some_components_of_nonmaterial_culture.pdf
- https://cdn.shopify.com/s/files/1/0482/3905/0906/files/sterilite_storage_containers_3_drawers.pdf
- https://cdn.shopify.com/s/files/1/0497/9094/3381/files/kill_shot_hack_mod_apk_download.pdf
- https://site-1039219.mozfiles.com/files/1039219/98090706209.pdf
- https://site-1040506.mozfiles.com/files/1040506/valifarivitobusodale.pdf
- https://site-1039308.mozfiles.com/files/1039308/72981520054.pdf
- https://site-1040612.mozfiles.com/files/1040612/fuguvatek.pdf
- https://site-1041766.mozfiles.com/files/1041766/37840768308.pdf
- https://site-1037266.mozfiles.com/files/1037266/sasebitowasanavesoti.pdf
- https://site-1039693.mozfiles.com/files/1039693/tasazoni.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f87171ed94f9.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f86f85a24e01.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f87083033e9a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1039219.mozfiles.com
- site-1040506.mozfiles.com
- site-1039308.mozfiles.com
- site-1040612.mozfiles.com
- site-1041766.mozfiles.com
- site-1037266.mozfiles.com
- site-1039693.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report