SUSPICIOUS — lowanige-dixujav.pdf
SUSPICIOUS — lowanige-dixujav.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
5a4e02c71849a21f3e636507fa392d13fe9ef2c8a2eaeec2516c8d0c2aea8bb6 - SHA-1:
98905718a3d0423bf7016dbf8afc7895f09f4ac1 - MD5:
0f3303892f89ceef8fbd0bb84d9f72e3 - ssdeep:
768:CgGzpDPpYwcfKgm6QHSOMo+ze3sP4qn9RJSr5I5lwiWs3kh2PYxUZCnOkbDBAR0S:fGFzppaBO8P/9vS6Ws0c4UYnOkbu0r27 - TLSH:
T153328CF36093ED5C7E8BAB436DAB25A62485C78C6127971048CC6B6CC4BC6BD7F10890 - Submitted as: lowanige-dixujav.pdf
- File type: pdf · Size: 44874 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=fireboy%20and%20watergirl%2010, https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/03b622.pdf, https://xibogunef.weebly.com/uploads/1/3/1/3/131398295/992b55e2d7207.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=fireboy%20and%20watergirl%2010
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/03b622.pdf
- https://xibogunef.weebly.com/uploads/1/3/1/3/131398295/992b55e2d7207.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/4256338.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/7302827.pdf
- https://roninuvanajeg.weebly.com/uploads/1/3/1/3/131379749/mibeniwirivaxe-nabisupo.pdf
- https://uploads.strikinglycdn.com/files/f9a96459-df9a-49e5-8a9e-196195981aae/nupediduvegaloxalokesuz.pdf
- https://uploads.strikinglycdn.com/files/39fcc487-b20c-40e4-84a2-b4494aa10985/bafemudewaw.pdf
- https://uploads.strikinglycdn.com/files/3583c9d9-c0db-4728-960f-e78c6e800cba/35531040484.pdf
- https://uploads.strikinglycdn.com/files/0e34e30f-0ebf-488e-9cd4-5cb5f1e42e46/12310313785.pdf
- https://uploads.strikinglycdn.com/files/cb88934a-c155-462e-b223-3ab320ca0c37/76458392361.pdf
- https://cdn.shopify.com/s/files/1/0484/6629/6986/files/flexible_packaging_industry_analysis.pdf
- https://cdn.shopify.com/s/files/1/0481/4598/9783/files/bojafuwasibajojisi.pdf
- https://cdn.shopify.com/s/files/1/0499/9666/0886/files/42218564913.pdf
- https://cdn.shopify.com/s/files/1/0485/8249/2325/files/eclipse_phase_backgrounds.pdf
- https://cdn.shopify.com/s/files/1/0486/0752/7077/files/bling_ring_imdb_parents_guide.pdf
- https://rojusonevupa.weebly.com/uploads/1/3/0/8/130814232/tozewekugodakoto.pdf
- https://leputixoted.weebly.com/uploads/1/3/2/6/132683438/kukuki_rejowalagige_xapotiz.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/wulegapo-fojinunapadija-jopugabo.pdf
- https://cdn-cms.f-static.net/uploads/4371020/normal_5f8a5150265d6.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f873629b33ad.pdf
- https://cdn-cms.f-static.net/uploads/4370302/normal_5f88c53b1489d.pdf
- https://cdn-cms.f-static.net/uploads/4369768/normal_5f8a866c56adc.pdf
- https://cdn-cms.f-static.net/uploads/4380411/normal_5f8b7ed923bd9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- pigogokeda.weebly.com
- xibogunef.weebly.com
- nobinetezo.weebly.com
- sesuwulot.weebly.com
- roninuvanajeg.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- rojusonevupa.weebly.com
- leputixoted.weebly.com
- nanorobudilason.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report