SUSPICIOUS — luzukugilotiwomexek.pdf
SUSPICIOUS — luzukugilotiwomexek.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
729981298634eacf79d62d915be130c1edf502517cf11aa515eefae5230680a4 - SHA-1:
ebb53ab6a02176a9bff5b24280dad0381fe9fc79 - MD5:
b6ba12d0a41cd0dfe89412ac965854fb - ssdeep:
768:AgGzpDCpwsQR6i1bJYnnwFkcuMbp84AppfdK346wmdF9ZlGDSW56zZPiT6PTc:NGF2pUDkFAUp8trdHZlGDe+6PTc - TLSH:
T1DB34AFF351A3ED8C7A4B6F43AE5301A9714AD789317297A054CC762DC0BC6BE6F10A60 - Submitted as: luzukugilotiwomexek.pdf
- File type: pdf · Size: 54442 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/lebugodoj_xufadijemorov_davubesezon_koravisawonub.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=2009%20ap%20chemistry%20free%20response, https://site-1039405.mozfiles.com/files/1039405/75866075127.pdf, https://site-1043218.mozfiles.com/files/1043218/25912009461.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=2009%20ap%20chemistry%20free%20response
- https://site-1039405.mozfiles.com/files/1039405/75866075127.pdf
- https://site-1043218.mozfiles.com/files/1043218/25912009461.pdf
- https://site-1039391.mozfiles.com/files/1039391/tunegaji.pdf
- https://site-1038985.mozfiles.com/files/1038985/29951845629.pdf
- https://site-1048473.mozfiles.com/files/1048473/nogoselidojagisodimuvola.pdf
- https://uploads.strikinglycdn.com/files/1b2f4f8c-ef27-44f9-9ec6-3d60d4b9ae3d/93615833564.pdf
- https://uploads.strikinglycdn.com/files/ab3fff0e-d528-46c5-82b0-ed76e6ecfddc/xumozej.pdf
- https://uploads.strikinglycdn.com/files/827d3235-fb08-49de-a557-45128ce1ede9/xulatiwit.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/lebugodoj_xufadijemorov_davubesezon_koravisawonub.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/2697538.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/13b897d65df.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/3cb113af6.pdf
- https://uploads.strikinglycdn.com/files/dfed9283-84af-4950-a881-5b53b95692a9/54865768335.pdf
- https://uploads.strikinglycdn.com/files/a116077b-ce83-464e-a2c4-92899fed8205/vekeni.pdf
- https://uploads.strikinglycdn.com/files/c91db1f8-8dde-4539-af79-1bbc971cbcc4/faburosa.pdf
- https://uploads.strikinglycdn.com/files/89e1d004-a419-4817-ad86-848d917403b2/ronetamuzumukajogagugopa.pdf
- https://uploads.strikinglycdn.com/files/00ed5545-8328-48de-a1b6-b0fd2a7575c6/87229142834.pdf
- https://cdn.shopify.com/s/files/1/0467/9837/3013/files/48677281582.pdf
- https://cdn.shopify.com/s/files/1/0432/7279/8373/files/corydon_intermediate_school.pdf
- https://cdn.shopify.com/s/files/1/0493/2036/2143/files/73032342876.pdf
- https://cdn.shopify.com/s/files/1/0480/3936/2719/files/random_sampling_worksheet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- site-1039405.mozfiles.com
- site-1043218.mozfiles.com
- site-1039391.mozfiles.com
- site-1038985.mozfiles.com
- site-1048473.mozfiles.com
- uploads.strikinglycdn.com
- povutepumik.weebly.com
- dimaxafazeza.weebly.com
- jufaxexave.weebly.com
- keniwuki.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report