SUSPICIOUS — korolalugisep.pdf
SUSPICIOUS — korolalugisep.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
81860e3b98cfd6f95bc2362d4024ecbdd77a7389f42c36c1a87cc00dfb0cd7b4 - SHA-1:
1ef1569c620103a4c10069eb89c11814a6a349cd - MD5:
1a1d15c69f2adb421e16c17a12ae18aa - ssdeep:
768:IgGzpDgqcN47SbPD1wP+Wmhj4ZIcaRvO2PMLQt44PeBu+R+F95XE:FGF8ASDDLhM6bGqC0JtrFfXE - TLSH:
T155328FF350A7DD9C3A8B6B07AAE72459914FC38D2137D7B04889671DC0B86BE6D00B51 - Submitted as: korolalugisep.pdf
- File type: pdf · Size: 47107 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=akkadian+language+dictionary+pdf, https://uploads.strikinglycdn.com/files/34d65919-d11d-4dd1-a747-1e23724ffe1a/56089170407.pdf, https://uploads.strikinglycdn.com/files/d60a2cc7-b5c7-4897-bc2a-949cd301d210/22236623350.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=akkadian+language+dictionary+pdf
- https://uploads.strikinglycdn.com/files/34d65919-d11d-4dd1-a747-1e23724ffe1a/56089170407.pdf
- https://uploads.strikinglycdn.com/files/d60a2cc7-b5c7-4897-bc2a-949cd301d210/22236623350.pdf
- https://uploads.strikinglycdn.com/files/9cc69fa9-8abf-49a6-b5a2-e11b334ecd83/91654202070.pdf
- https://uploads.strikinglycdn.com/files/66db6f10-1996-4a14-871a-ca933d6b43e8/bimixitirazajerozewowaka.pdf
- https://uploads.strikinglycdn.com/files/68042879-deac-4d27-bbda-4e91dc91fec2/18453860309.pdf
- https://uploads.strikinglycdn.com/files/656a04fb-3301-4265-a333-7ed7f40b4f11/vakidanuxe.pdf
- https://uploads.strikinglycdn.com/files/20736687-3724-4f62-acd8-9d5702331e61/fegoxibedenulabax.pdf
- https://uploads.strikinglycdn.com/files/080b001b-8101-4600-afc4-9c0dae8e2604/jivasafenuredebepatujofe.pdf
- https://uploads.strikinglycdn.com/files/4faef74c-5d26-42ac-9a38-6cbd999f010e/67460517195.pdf
- https://uploads.strikinglycdn.com/files/3b9d70e5-7c8a-4110-b967-e82f6cf8a0a1/22024861667.pdf
- https://uploads.strikinglycdn.com/files/3e2aa961-98df-4a15-97f8-357be6ffb968/3761726428.pdf
- https://uploads.strikinglycdn.com/files/4a1a89d7-e360-4427-a52c-1119e9503266/xepedelovomewu.pdf
- https://uploads.strikinglycdn.com/files/719ddbed-306f-49cc-8daa-3bb14502dfb7/bukidupigolas.pdf
- https://uploads.strikinglycdn.com/files/ec1cbd03-35be-4f41-850a-f5be8713a60a/xigupelibufewupibet.pdf
- https://uploads.strikinglycdn.com/files/b957d646-b005-4118-b851-78a45004ebc6/95140387643.pdf
- https://uploads.strikinglycdn.com/files/7d101ac4-0889-4d50-b0ae-0371a678af3a/64300516297.pdf
- https://uploads.strikinglycdn.com/files/19f63737-3327-46ad-b38e-5d7b4b3d283d/gilumifevijir.pdf
- https://uploads.strikinglycdn.com/files/80a2a3bb-2bed-4d87-9e6f-f8cbd32c7e02/mijarojuzetovoniduto.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report