SUSPICIOUS — lebugodoj_xufadijemorov_davubesezon_koravisawonub.pdf
SUSPICIOUS — lebugodoj_xufadijemorov_davubesezon_koravisawonub.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
8799b999e17300ce72fa7fb133172aa1cddf3ff7ff7e89ee546f53c1956b3b45 - SHA-1:
54adc49309a50e66da480c41bc9663459b584e00 - MD5:
c23bcb0cf4474d3817db3c2a85251e5d - ssdeep:
1536:XGFZeoUdEeItBrGmKMJlCowCFsPV2WrBlPkTNJ:2FZe4PrFnlCWFstlMn - TLSH:
T1E4359DF391A7DDCCBAC69B47A8FB1168604ADB4C613697D04488772CC4BCABD7E10950 - Submitted as: lebugodoj_xufadijemorov_davubesezon_koravisawonub.pdf
- File type: pdf · Size: 60692 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=despicable%20me%20minion%20rush%20hack%20apk, https://cdn-cms.f-static.net/uploads/4365540/normal_5f86f89f593a5.pdf, https://cdn-cms.f-static.net/uploads/4366041/normal_5f86f85fbbce5.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=despicable%20me%20minion%20rush%20hack%20apk
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f86f89f593a5.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f86f85fbbce5.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f8709936604b.pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f870dd22e987.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f870e275a6c5.pdf
- https://cdn.shopify.com/s/files/1/0484/1347/4984/files/rasanupuzuxalefifeju.pdf
- https://uploads.strikinglycdn.com/files/4915723f-1f0e-46bb-8f55-abd5894b09ad/53616459837.pdf
- https://uploads.strikinglycdn.com/files/fd6b71eb-07b1-4bb3-b164-a811f8ad920b/murigidis.pdf
- https://cdn.shopify.com/s/files/1/0435/7105/2703/files/gelowakuxom.pdf
- https://cdn.shopify.com/s/files/1/0482/9331/4722/files/54330547217.pdf
- https://cdn.shopify.com/s/files/1/0437/0622/0712/files/ioun_stone_of_protection_price.pdf
- https://cdn.shopify.com/s/files/1/0438/8785/3720/files/gideon_welles_school_lunch_menu.pdf
- https://cdn.shopify.com/s/files/1/0480/2812/3295/files/lilasudosupafipog.pdf
- https://uploads.strikinglycdn.com/files/f497522d-070e-4fc1-a271-389ce7aa5748/xutovo.pdf
- https://uploads.strikinglycdn.com/files/a22b771e-20fe-4022-a3cf-c686180ff27e/disazodabapalulaposidu.pdf
- https://uploads.strikinglycdn.com/files/d6f619d8-dbc1-43f0-9686-d9de18a582d4/pijudezuwe.pdf
- https://uploads.strikinglycdn.com/files/9bced844-5e9f-4836-8488-5b966b67c9c8/18980693233.pdf
- https://uploads.strikinglycdn.com/files/7a2480a3-13f5-44c4-a688-20951bcc095f/78254428380.pdf
- https://site-1040326.mozfiles.com/files/1040326/64579885845.pdf
- https://site-1041782.mozfiles.com/files/1041782/tujawaralobokox.pdf
- https://site-1036632.mozfiles.com/files/1036632/fisulofamoza.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1040326.mozfiles.com
- site-1041782.mozfiles.com
- site-1036632.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report