SUSPICIOUS — lafogetudeziz_xonilewutufuji.pdf
SUSPICIOUS — lafogetudeziz_xonilewutufuji.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4ef827b9f9783ccec0491a0142d7a20ad1add3f50f50d1afb6a9677496e3604b - SHA-1:
03fdbb938be83f6888d18d03cf56b27c6df08564 - MD5:
a72da6abf0bb1be251124737cba08f1a - ssdeep:
768:ugGzpDwp0a5OULnHqN2oH/xABA9xcf/wzYUnxR9AusjKiNrir1z10DFaU7HiPRV8:LGF0pexA5fnWzWjNNU1KJHiPblm - TLSH:
T13833BFF350D7EC8C7BCAEF239CEA109954CAC7886123AB900599776CD4BC66C6E50C61 - Submitted as: lafogetudeziz_xonilewutufuji.pdf
- File type: pdf · Size: 49509 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=boerewors%20roll%20business%20plan%20pdf, https://uploads.strikinglycdn.com/files/f5d60914-2ae2-4145-8378-6966e2a71322/18184257976.pdf, https://uploads.strikinglycdn.com/files/12697c31-47c2-4d40-a0e7-4357c2133590/70836104378.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=boerewors%20roll%20business%20plan%20pdf
- https://uploads.strikinglycdn.com/files/f5d60914-2ae2-4145-8378-6966e2a71322/18184257976.pdf
- https://uploads.strikinglycdn.com/files/12697c31-47c2-4d40-a0e7-4357c2133590/70836104378.pdf
- https://uploads.strikinglycdn.com/files/5fe22b2b-8c76-41ba-911c-d8f1ba7020e2/mopiminixotejigubak.pdf
- https://uploads.strikinglycdn.com/files/005c18db-18d2-4247-8e5d-362c8646e89c/nulavowizow.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f8732ddbad2b.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f87765a8efda.pdf
- https://cdn-cms.f-static.net/uploads/4368762/normal_5f8814dbed15e.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f875f7c10e00.pdf
- https://cdn-cms.f-static.net/uploads/4368949/normal_5f87b66dd4d6b.pdf
- https://site-1039414.mozfiles.com/files/1039414/69595933728.pdf
- https://site-1041381.mozfiles.com/files/1041381/wireless_android_auto_hyundai.pdf
- https://site-1036656.mozfiles.com/files/1036656/68343429472.pdf
- https://cdn.shopify.com/s/files/1/0480/9441/2963/files/75608315804.pdf
- https://cdn.shopify.com/s/files/1/0434/6806/2872/files/aia_travel_insurance_claim.pdf
- https://cdn.shopify.com/s/files/1/0496/0793/4103/files/scholastic_book_wizard_scanner.pdf
- https://cdn.shopify.com/s/files/1/0481/3556/9571/files/lg_stylo_4_stylus_pen.pdf
- https://cdn.shopify.com/s/files/1/0266/9435/3088/files/inscom_csm_schmitz_death.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/sozusor-gofizulukan-pisobal.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/fibawubaxavuvabu.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zidebesirolabavo.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/f9007.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/lanadez.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1039414.mozfiles.com
- site-1041381.mozfiles.com
- site-1036656.mozfiles.com
- cdn.shopify.com
- nogafuku.weebly.com
- keniwuki.weebly.com
- jawasolasazilem.weebly.com
- dutitujazekap.weebly.com
- guwomenod.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report