SUSPICIOUS — letad_wegimanoze.pdf
SUSPICIOUS — letad_wegimanoze.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
36e2cc1eb58ea1053e964b9b32bc88d5ac8e61b201f841b07910ec6932a717e6 - SHA-1:
632b58cf5488d2acbf3da510927d233868af91e8 - MD5:
ccd2247f4d0ff63967608e4d5d0dc1dc - ssdeep:
768:xqGgGzpDCeaInf5tXc2qvPxtoUHCEyfK7YYdeaZifRRXKfM1T4TcF+:xyGFmeE2cxuUk1YoWiJR6fMOQF+ - TLSH:
T12E329EF32497ED8C398B9B03ADFB1469548AC38C62329B60448C777DC4BC2BCAE50951 - Submitted as: letad_wegimanoze.pdf
- File type: pdf · Size: 46831 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=paramahansa%20yogananda%20journey%20to%20self%20realization%20pdf, https://uploads.strikinglycdn.com/files/66a188a2-1ba7-44da-b541-7707c4af275a/83066687113.pdf, https://uploads.strikinglycdn.com/files/7978efc5-f8ef-4714-a26a-e654d5ecf115/45696939780.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=paramahansa%20yogananda%20journey%20to%20self%20realization%20pdf
- https://uploads.strikinglycdn.com/files/66a188a2-1ba7-44da-b541-7707c4af275a/83066687113.pdf
- https://uploads.strikinglycdn.com/files/7978efc5-f8ef-4714-a26a-e654d5ecf115/45696939780.pdf
- https://uploads.strikinglycdn.com/files/43cd3a26-68a7-42fb-b986-edde88850d5f/wovisevebilitogegewixamar.pdf
- https://cdn.shopify.com/s/files/1/0483/7087/6576/files/leisure_bay_spas_celebrity_owners_manual.pdf
- https://uploads.strikinglycdn.com/files/79b5eddb-eede-45f7-b00e-df9062f5022f/28960466841.pdf
- https://uploads.strikinglycdn.com/files/ef8bde89-174c-4b9a-98f5-a2f215550565/aatagara_kannada_movie_cast.pdf
- https://uploads.strikinglycdn.com/files/4d14deb8-fc32-4e0a-a0fa-aae43ff5a22e/pimolajovupar.pdf
- https://uploads.strikinglycdn.com/files/807c6119-5d7f-4e0e-8e8d-032f2cf0131c/rekozezi.pdf
- https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/e4350fb0.pdf
- https://zuxizakubapepo.weebly.com/uploads/1/3/4/3/134317428/ff19d52aae.pdf
- https://misutinulil.weebly.com/uploads/1/3/1/4/131407711/6241945.pdf
- https://nagigezivozitos.weebly.com/uploads/1/3/4/3/134340852/bupitinupo-gadedegefarewa-bixiridem.pdf
- https://cdn.shopify.com/s/files/1/0465/0860/5590/files/45848046719.pdf
- https://cdn.shopify.com/s/files/1/0434/0586/9208/files/zofapeberejirexawur.pdf
- https://cdn.shopify.com/s/files/1/0494/9160/7711/files/encyclopedia_brown_online.pdf
- https://cdn.shopify.com/s/files/1/0501/4755/7541/files/script_lua_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0436/5592/1817/files/otto_snow.pdf
- https://gesinanafu.weebly.com/uploads/1/3/4/4/134481382/pududamofazavob_jumaselukuxipa_verawul.pdf
- https://winomumamo.weebly.com/uploads/1/3/1/0/131070375/7987181.pdf
- https://wosezobar.weebly.com/uploads/1/3/1/8/131856012/3753809d3.pdf
- https://lulitetuxopibol.weebly.com/uploads/1/3/1/1/131164377/banapugemet-mobex.pdf
- https://kilesikawagex.weebly.com/uploads/1/3/4/3/134372597/magetulofonasuza.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- fotejisatowonu.weebly.com
- zuxizakubapepo.weebly.com
- misutinulil.weebly.com
- nagigezivozitos.weebly.com
- gesinanafu.weebly.com
- winomumamo.weebly.com
- wosezobar.weebly.com
- lulitetuxopibol.weebly.com
- kilesikawagex.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report