SUSPICIOUS — lufifisa.pdf
SUSPICIOUS — lufifisa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8ea45c6a92746bc0cdfe4cbdfa6ce9becc8e89aac86a154e6d02eab8f55f9a95 - SHA-1:
df7513c15670bc61ba231b0965392d5fbcf0386d - MD5:
60f72c0e6499d7243b297d59d2231a35 - ssdeep:
3072:WF/z4/koqIgkN08bwk0hGBPYz+3r4b7jc:m74/6IgC0wohGBPVrV - TLSH:
T1193CE0F38457ED4C77CB9F932EA6251D6049E7886022E760648CAB2CC5BC6BD3E40A11 - Submitted as: lufifisa.pdf
- File type: pdf · Size: 114505 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/df091ea5-7c36-4b4d-896f-6de7120d78ec/denukivonusijadowofil.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=anti%20tyrosinase%20pdf, https://lotogifivetizub.weebly.com/uploads/1/3/4/3/134309957/tababesup_benuvesinokoga_kiluzezujikurul.pdf, https://wubaruduxosekur.weebly.com/uploads/1/3/4/4/134484821/jipetaxovepotapapu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=anti%20tyrosinase%20pdf
- https://s3.amazonaws.com/vatakefojunib/advantages_of_mixed_economy.pdf
- https://lotogifivetizub.weebly.com/uploads/1/3/4/3/134309957/tababesup_benuvesinokoga_kiluzezujikurul.pdf
- https://wubaruduxosekur.weebly.com/uploads/1/3/4/4/134484821/jipetaxovepotapapu.pdf
- https://cdn.shopify.com/s/files/1/0493/7210/2822/files/windows_9_launcher_for_android_apk.pdf
- https://gejatovuri.weebly.com/uploads/1/3/1/4/131406669/7470081.pdf
- https://uploads.strikinglycdn.com/files/df091ea5-7c36-4b4d-896f-6de7120d78ec/denukivonusijadowofil.pdf
- https://s3.amazonaws.com/pozokimepe/ipl_2019_schedule_player_list.pdf
- https://cdn.shopify.com/s/files/1/0437/0222/3013/files/1931778241.pdf
- https://uploads.strikinglycdn.com/files/0a3b62ee-26a5-4cf1-b9fb-db71c708b87f/6686663934.pdf
- https://s3.amazonaws.com/tetazino/guide_agriculture_biologique.pdf
- https://s3.amazonaws.com/vavebufevodutob/xanezegos.pdf
- https://s3.amazonaws.com/moduxanakuri/accounting_research_topics.pdf
- https://cdn.shopify.com/s/files/1/0427/9926/8003/files/a_concise_guide_to_macroeconomics_david_moss_download.pdf
- https://s3.amazonaws.com/dobesogum/multiplying_binomial_by_binomial_worksheet.pdf
- https://s3.amazonaws.com/fasanag/65080542133.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/pulod.pdf
- https://s3.amazonaws.com/minaxigevani/wapigedajul.pdf
- https://cdn-cms.f-static.net/uploads/4383807/normal_5f8e66a28bae5.pdf
- https://uploads.strikinglycdn.com/files/670cf705-64c9-41b0-bf4d-9282823d937e/kubaw.pdf
- https://s3.amazonaws.com/remeranexe/56322344957.pdf
- https://cdn-cms.f-static.net/uploads/4368468/normal_5f87c20f722ce.pdf
- https://s3.amazonaws.com/samopakamefap/kisuwilipelapabosavimaxul.pdf
- https://cdn.shopify.com/s/files/1/0476/7626/0518/files/zajuvotobisatajewixukigul.pdf
- https://uploads.strikinglycdn.com/files/fe923529-179b-4962-b215-e7d3606ba5e1/meretami.pdf
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- lotogifivetizub.weebly.com
- wubaruduxosekur.weebly.com
- cdn.shopify.com
- gejatovuri.weebly.com
- uploads.strikinglycdn.com
- pigogokeda.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report