SUSPICIOUS — lutamobojuz.pdf
SUSPICIOUS — lutamobojuz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
8d1f7dd5eddafdc3f641b2835c9aed5d8b3093ac7e08f6457ad8341791b1a923 - SHA-1:
1ae43ec8c65831ae9b94fef6b3b3dc7b818d1df5 - MD5:
6e25b7c8f0fc016d6fe1b44b79e5cc24 - ssdeep:
768:TgGzpDupCL3KTLMEy0GGGJYiXTAmbYex3U1Dc4RLwWsKuR4lsG+8VRuDETD0UABR:sGFSpwGQFbYa3z4RLwWsKuOsz8CUABR - TLSH:
T10732AEF74197EC4C7A86DB136CDA10AA248AC78D72329764489C373DE57C27EAF00A50 - Submitted as: lutamobojuz.pdf
- File type: pdf · Size: 46913 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=alcohol+related+liver+disease+guidelines, https://cdn.shopify.com/s/files/1/0431/4257/8332/files/65351884538.pdf, https://cdn.shopify.com/s/files/1/0459/7225/8983/files/92485044705.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=alcohol+related+liver+disease+guidelines
- https://cdn.shopify.com/s/files/1/0431/4257/8332/files/65351884538.pdf
- https://cdn.shopify.com/s/files/1/0459/7225/8983/files/92485044705.pdf
- https://cdn.shopify.com/s/files/1/0428/0378/9991/files/purifying_salt_ffx.pdf
- https://cdn.shopify.com/s/files/1/0483/0566/8260/files/toilet_flange_repair_ring_installation.pdf
- https://cdn.shopify.com/s/files/1/0431/2052/5461/files/83824762587.pdf
- https://cdn.shopify.com/s/files/1/0438/9987/9576/files/63238047530.pdf
- https://cdn.shopify.com/s/files/1/0465/9252/4453/files/autodesk_sketchbook_pro_hack_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0495/5930/6392/files/circulatory_system_diagram_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0497/2992/9377/files/diatest_split_ball.pdf
- https://site-1037903.mozfiles.com/files/1037903/porujuxofunedagok.pdf
- https://site-1037069.mozfiles.com/files/1037069/zofudukajotuvexaretinagar.pdf
- https://site-1037079.mozfiles.com/files/1037079/fifunizaropukujujafizosox.pdf
- https://site-1040884.mozfiles.com/files/1040884/bogusif.pdf
- https://site-1036862.mozfiles.com/files/1036862/sivubokoxukusuzo.pdf
- https://site-1036840.mozfiles.com/files/1036840/5358168169.pdf
- https://site-1042768.mozfiles.com/files/1042768/vinogulerejoxesow.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1037903.mozfiles.com
- site-1037069.mozfiles.com
- site-1037079.mozfiles.com
- site-1040884.mozfiles.com
- site-1036862.mozfiles.com
- site-1036840.mozfiles.com
- site-1042768.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report