SUSPICIOUS — lafax.pdf
SUSPICIOUS — lafax.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
63dad9d7ed71194a96dc5be5f15b0432fad390ae5e6fd416be7bf8af4ad0b36d - SHA-1:
7e46d7e6ace5c16c85d92f8dfd78262d265600f1 - MD5:
757566940c4bc1bb49cc898f6ee5226f - ssdeep:
1536:xGFppw9rxbKW+HTNmHQM1soqJlbuOnK/:UFppwVxKpHJmHZ0bXO - TLSH:
T199338EF340A7ED4C7A8B9F43ADAB1598744AC78DA1239B900488773CD47C6BE6F40911 - Submitted as: lafax.pdf
- File type: pdf · Size: 49866 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=pictogramme%20de%20s%C3%A9curit%C3%A9%20pdf, https://cdn-cms.f-static.net/uploads/4370280/normal_5f8a6b3ee6bc6.pdf, https://cdn-cms.f-static.net/uploads/4367268/normal_5f875687424d7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=pictogramme%20de%20s%C3%A9curit%C3%A9%20pdf
- https://cdn-cms.f-static.net/uploads/4370280/normal_5f8a6b3ee6bc6.pdf
- https://cdn-cms.f-static.net/uploads/4367268/normal_5f875687424d7.pdf
- https://cdn-cms.f-static.net/uploads/4367294/normal_5f8920ab68801.pdf
- https://zadumeredevasax.weebly.com/uploads/1/3/1/4/131453870/nomujejem-woburum-wawoxefikilime-pesexesa.pdf
- https://kiseridebajesa.weebly.com/uploads/1/3/1/4/131408791/xidofijeji_ribasudutobume_fitezefoxefer.pdf
- https://pudegubazamase.weebly.com/uploads/1/3/1/1/131163945/439013.pdf
- https://xogexemufak.weebly.com/uploads/1/3/1/4/131437987/3d8f4319c7.pdf
- https://cdn-cms.f-static.net/uploads/4367279/normal_5f87389b28a48.pdf
- https://cdn-cms.f-static.net/uploads/4381297/normal_5f8ca2a14680a.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f8d4aac220d9.pdf
- https://cdn-cms.f-static.net/uploads/4373519/normal_5f8908c9cdd1e.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f9094233ce1f.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/8626484.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/0c18874847f.pdf
- https://vodiwisilob.weebly.com/uploads/1/3/2/6/132681054/kabumo.pdf
- https://jubunukaf.weebly.com/uploads/1/3/1/4/131483214/8278019.pdf
- https://uploads.strikinglycdn.com/files/ff3a7be1-55f6-45f3-9d89-e109682b8fd5/13367240223.pdf
- https://uploads.strikinglycdn.com/files/021240d8-2095-4d0f-aa37-0fedb6fff74c/70153742199.pdf
- https://uploads.strikinglycdn.com/files/278133da-80f9-4ab8-9fb5-02d9d0535b46/23552263525.pdf
- https://uploads.strikinglycdn.com/files/61bb0787-19f5-4ff9-b231-2afce35b931c/raxavojilapodijemojulez.pdf
- https://cdn.shopify.com/s/files/1/0434/0314/9479/files/teachers_day_odia_speech.pdf
- https://cdn.shopify.com/s/files/1/0497/5152/3482/files/zalukozop.pdf
- https://cdn.shopify.com/s/files/1/0266/7819/8464/files/sbs_tv_guide_sunday_night.pdf
- https://cdn.shopify.com/s/files/1/0501/5289/8739/files/bilonukuve.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- zadumeredevasax.weebly.com
- kiseridebajesa.weebly.com
- pudegubazamase.weebly.com
- xogexemufak.weebly.com
- jiwepurojal.weebly.com
- dutitujazekap.weebly.com
- vodiwisilob.weebly.com
- jubunukaf.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report