SUSPICIOUS — lonew_xexasar_benavuvi_kipako.pdf
SUSPICIOUS — lonew_xexasar_benavuvi_kipako.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
720f1247f5a5d6e381892c170dea726d6db76cacc80193fd5b5040393c5e6e2d - SHA-1:
6391d63b94299485ce682e329dbf7b341a16a89b - MD5:
92a90da31f79540aa33e3866cb8130e9 - ssdeep:
768:iegGzpD/p9/CzTSdU9xxAsReZJWnIrz7CdIqW0Zaauro0B23mnlXqgGVAwSJK:gGFrpDZJWnIrPCj3uro0gWnlXHGVAwSw - TLSH:
T1BA329EF360D7DD4D798A9F13AD96262A5289D28DA236D36004DC772CC9FC2BD7E10860 - Submitted as: lonew_xexasar_benavuvi_kipako.pdf
- File type: pdf · Size: 46233 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=android%20data%20recovery, https://cdn.shopify.com/s/files/1/0482/2296/1816/files/zazuwuxoxemufagoxu.pdf, https://cdn.shopify.com/s/files/1/0434/3224/7457/files/dowixuxitowekivolumatej.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=android%20data%20recovery
- https://cdn.shopify.com/s/files/1/0482/2296/1816/files/zazuwuxoxemufagoxu.pdf
- https://cdn.shopify.com/s/files/1/0434/3224/7457/files/dowixuxitowekivolumatej.pdf
- https://cdn.shopify.com/s/files/1/0434/3362/3708/files/owen_funeral_home_cartersville_ga.pdf
- https://cdn.shopify.com/s/files/1/0496/1386/5124/files/skyrim_add_skill_points_cheat_code.pdf
- https://cdn.shopify.com/s/files/1/0432/8855/9782/files/alpine_swamp_cooler.pdf
- https://site-1039430.mozfiles.com/files/1039430/97227878553.pdf
- https://site-1036975.mozfiles.com/files/1036975/97446479945.pdf
- https://uploads.strikinglycdn.com/files/2a5753e8-f5ac-4a32-9ac0-b0935c202c2f/fisuzirif.pdf
- https://uploads.strikinglycdn.com/files/06015023-ae5e-45e9-9677-1d87021ad924/wovuve.pdf
- https://uploads.strikinglycdn.com/files/d8efac68-ab65-4fdd-8cd2-f126a94f085d/tidagikibugabepolovelin.pdf
- https://uploads.strikinglycdn.com/files/5142ce0b-c3dc-4571-b99b-6c5575f92605/20490005780.pdf
- https://uploads.strikinglycdn.com/files/81dcad9d-fec0-4933-8dfa-f14d39d90721/88503867160.pdf
- https://misopiwulasi.weebly.com/uploads/1/3/1/8/131856666/fubufusa_veruwuviwu_tiwidajuk_miputilifiguxif.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/4606116.pdf
- https://rajomiluti.weebly.com/uploads/1/3/2/6/132682989/730211.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/marema-zevaz.pdf
- https://topodomero.weebly.com/uploads/1/3/2/6/132696018/7180503.pdf
- https://cdn-cms.f-static.net/uploads/4367914/normal_5f88bd174bc18.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f86fc85368cd.pdf
- https://cdn-cms.f-static.net/uploads/4367625/normal_5f87575fd9742.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f87052517efc.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f87252592983.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f872a3e0f063.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1039430.mozfiles.com
- site-1036975.mozfiles.com
- uploads.strikinglycdn.com
- misopiwulasi.weebly.com
- wepugimi.weebly.com
- rajomiluti.weebly.com
- zesopupejilit.weebly.com
- topodomero.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report