SUSPICIOUS — lepeburoni.pdf
SUSPICIOUS — lepeburoni.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
75849d7996429e711d082ed2803916073db94f991bb3652304318db4f1c4457d - SHA-1:
4e06b1719411f2cd22bfbc256799d26f15a2a6db - MD5:
261c901c6898336004283638f947bf9e - ssdeep:
768:XgGzpDuf4wiEigzskMgxcm5Lfj6tSD6YgoOYb5FB:wGFKfCEOmdLf9DLJb5FB - TLSH:
T198329EF3A167DC4C7A8BAB136DE6204D508AD64C5172A37498887B2DD4BC3BC7F40A61 - Submitted as: lepeburoni.pdf
- File type: pdf · Size: 44072 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=paint+tool+sai+2+full+mega, https://site-1036786.mozfiles.com/files/1036786/bepawavotele.pdf, https://site-1037073.mozfiles.com/files/1037073/sinujilufotokupazawizerab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=paint+tool+sai+2+full+mega
- https://site-1036786.mozfiles.com/files/1036786/bepawavotele.pdf
- https://site-1037073.mozfiles.com/files/1037073/sinujilufotokupazawizerab.pdf
- https://site-1039207.mozfiles.com/files/1039207/82475360966.pdf
- https://site-1038925.mozfiles.com/files/1038925/vetanuwumudusemitaremon.pdf
- https://site-1037079.mozfiles.com/files/1037079/62382672782.pdf
- https://site-1036820.mozfiles.com/files/1036820/gepodumiberu.pdf
- https://site-1037022.mozfiles.com/files/1037022/30717877663.pdf
- https://site-1036680.mozfiles.com/files/1036680/94930074432.pdf
- https://site-1038955.mozfiles.com/files/1038955/3370899665.pdf
- https://site-1037251.mozfiles.com/files/1037251/11249249050.pdf
- https://uploads.strikinglycdn.com/files/ee938ce2-d4fb-4cae-8e55-8ee41f28b143/83368924836.pdf
- https://uploads.strikinglycdn.com/files/eccb2e12-463e-4627-8ec5-ab46b668fc3c/62830620004.pdf
- https://uploads.strikinglycdn.com/files/1c7173c2-df11-4f89-a5a3-a02184ee6e31/99704034460.pdf
- https://uploads.strikinglycdn.com/files/90c57116-6fe2-4112-ac7e-036ecf518c42/dodetibabopabum.pdf
- https://uploads.strikinglycdn.com/files/5cfc21c6-b808-4d32-961a-cf515d9dd003/wakoxuluzomanudab.pdf
- https://site-1036969.mozfiles.com/files/1036969/25141904302.pdf
- https://site-1039952.mozfiles.com/files/1039952/16439356084.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036786.mozfiles.com
- site-1037073.mozfiles.com
- site-1039207.mozfiles.com
- site-1038925.mozfiles.com
- site-1037079.mozfiles.com
- site-1036820.mozfiles.com
- site-1037022.mozfiles.com
- site-1036680.mozfiles.com
- site-1038955.mozfiles.com
- site-1037251.mozfiles.com
- uploads.strikinglycdn.com
- site-1036969.mozfiles.com
- site-1039952.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report