SUSPICIOUS — larerezufedi.pdf
SUSPICIOUS — larerezufedi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7923104f0a85d473161b6b32a6bb6302feaf537850a058b50edc53d5943e3d35 - SHA-1:
cfbe2ea1fa2fc1571f9d06a02319ff49736a86aa - MD5:
0718cf9a2279861e610df1becc62314d - ssdeep:
768:HgGzpDrpViujsmr+V8LFtV6Mx5z9dZAJAIkDhax14cf:AGFHpME5D9ta14cf - TLSH:
T120308EF300A7ED8E7BCBAB47A9B71165214AC34D6132EBA0188C362CD5BC5BD7E10951 - Submitted as: larerezufedi.pdf
- File type: pdf · Size: 37040 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=a%20dog, https://uploads.strikinglycdn.com/files/a6313014-0bb4-461e-90ca-7302c90e10ad/17700551531.pdf, https://uploads.strikinglycdn.com/files/62364e43-6382-45c8-9d30-f5b70965189f/88406112680.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=a%20dog
- https://uploads.strikinglycdn.com/files/a6313014-0bb4-461e-90ca-7302c90e10ad/17700551531.pdf
- https://uploads.strikinglycdn.com/files/62364e43-6382-45c8-9d30-f5b70965189f/88406112680.pdf
- https://uploads.strikinglycdn.com/files/7f7d8954-759f-4e45-9d65-14acec18512e/rebozorudadupasamad.pdf
- https://uploads.strikinglycdn.com/files/b464ba08-d5a9-4d36-bacd-1573eedec6db/22470624798.pdf
- https://uploads.strikinglycdn.com/files/5e7d057c-0af7-4b7b-aa05-75d1feb1f64b/63517425279.pdf
- https://uploads.strikinglycdn.com/files/2d1a60b9-1710-4353-9ad7-bb13c5c14a96/24627338065.pdf
- https://uploads.strikinglycdn.com/files/c78f3ca6-bcbe-4365-b03b-201c8e6410d0/fipudefunekiragesatib.pdf
- https://uploads.strikinglycdn.com/files/0459d9e8-6c86-49aa-b3ea-3dab4a2f3501/bopeb.pdf
- https://cdn.shopify.com/s/files/1/0496/2874/1803/files/violet_vs_purple.pdf
- https://cdn.shopify.com/s/files/1/0439/0649/8728/files/153516484.pdf
- https://cdn.shopify.com/s/files/1/0429/4557/7116/files/41912069316.pdf
- https://cdn.shopify.com/s/files/1/0435/1436/4059/files/school_wars_hacked_unblocked.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f877c4fb7ea1.pdf
- https://cdn-cms.f-static.net/uploads/4370746/normal_5f890b2a7ee87.pdf
- https://cdn.shopify.com/s/files/1/0485/0155/5355/files/voltaire_zadig_english.pdf
- https://cdn.shopify.com/s/files/1/0437/9066/3832/files/kuvojusedoreti.pdf
- https://cdn.shopify.com/s/files/1/0493/4280/8218/files/voxidimubizumeno.pdf
- https://cdn.shopify.com/s/files/1/0485/0185/0273/files/metsa_tissue_krapkowice_dyrektor.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report