SUSPICIOUS — fukakix_lobonagoke_voxajutafetufos_xujimozoxivid.pdf
SUSPICIOUS — fukakix_lobonagoke_voxajutafetufos_xujimozoxivid.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
67697017e05c7051451e01921c79bf122b18b03ec2f85a885bd0170c3b8c6e5d - SHA-1:
7228c7c4df87f293ed6069e42934b45852e49b7c - MD5:
5ccec782c820380c3b457914e4874bf5 - ssdeep:
768:YgGzpDzpTBLGC+kf5STwATesuVcxJMr/P8zUA6eiiju1ap/oTuYnY:1GFfpT1VV0JkcQgiijjyTuYnY - TLSH:
T134326CF35063ED8C7A8AAF036DEF292D4189D6486162A764949C772CC07C7BD7F10A21 - Submitted as: fukakix_lobonagoke_voxajutafetufos_xujimozoxivid.pdf
- File type: pdf · Size: 43989 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=kanye%20late%20registration%20zip, https://cdn.shopify.com/s/files/1/0501/5679/8117/files/6550177499.pdf, https://cdn.shopify.com/s/files/1/0434/1389/7372/files/takem.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=kanye%20late%20registration%20zip
- https://cdn.shopify.com/s/files/1/0501/5679/8117/files/6550177499.pdf
- https://cdn.shopify.com/s/files/1/0434/1389/7372/files/takem.pdf
- https://cdn.shopify.com/s/files/1/0429/2270/5055/files/distance_and_displacement_lab_activity_answers.pdf
- https://cdn.shopify.com/s/files/1/0429/5367/0822/files/audacity_manual_deutsch_download.pdf
- https://site-1036751.mozfiles.com/files/1036751/81233563261.pdf
- https://site-1042429.mozfiles.com/files/1042429/sikeko.pdf
- https://site-1036839.mozfiles.com/files/1036839/70495452950.pdf
- https://site-1038467.mozfiles.com/files/1038467/73761205530.pdf
- https://site-1043324.mozfiles.com/files/1043324/gevez.pdf
- https://site-1036632.mozfiles.com/files/1036632/86860358700.pdf
- https://site-1043365.mozfiles.com/files/1043365/kemuwaromobasozukobi.pdf
- https://site-1042584.mozfiles.com/files/1042584/23949961599.pdf
- https://site-1040396.mozfiles.com/files/1040396/lalizofozixegatunujaj.pdf
- https://uploads.strikinglycdn.com/files/b381fb48-41bc-4c1c-8516-8a3b95322e63/lonifibame.pdf
- https://uploads.strikinglycdn.com/files/fb6ee887-b56e-4480-92ef-12cdfff4f48a/72372408111.pdf
- https://uploads.strikinglycdn.com/files/be1ab212-e5e5-4d17-876d-4fbc04ad32e1/39002599483.pdf
- https://uploads.strikinglycdn.com/files/cf06cd20-8177-460a-be7f-6fc5f495d9d2/vebepinoxija.pdf
- https://uploads.strikinglycdn.com/files/16c426e4-b329-47bc-be19-ceb17c129f70/73962404301.pdf
- https://uploads.strikinglycdn.com/files/b2c88789-ecc8-41f9-81d5-3013f9e36835/vowudajoxufemativukotowa.pdf
- https://uploads.strikinglycdn.com/files/557b16ef-fe8f-4d30-ab0d-b236a02a5615/95699624677.pdf
- https://uploads.strikinglycdn.com/files/6306178c-0430-4803-b257-aa5db17bda33/94100242109.pdf
- https://uploads.strikinglycdn.com/files/9d60abd8-ccee-48ca-85e8-24ae474d5f99/zokom.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1036751.mozfiles.com
- site-1042429.mozfiles.com
- site-1036839.mozfiles.com
- site-1038467.mozfiles.com
- site-1043324.mozfiles.com
- site-1036632.mozfiles.com
- site-1043365.mozfiles.com
- site-1042584.mozfiles.com
- site-1040396.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report