SUSPICIOUS — lelukudere-luneliwusupoj-tesapug-ledetomuvovap.pdf
SUSPICIOUS — lelukudere-luneliwusupoj-tesapug-ledetomuvovap.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
92cc4d6301b4a2e22017c1289e2af87bbd292d2eb001d7364e9ac48660fc63ab - SHA-1:
843b4743142f341b2ef537f74c97ed7ebdac082d - MD5:
b42a805403d4496227562a6f63526f88 - ssdeep:
768:TgGzpDbped41PrSsjWErdREmCzn9/p9vLpNWj+ot3Ma0r:sGF3ptRaVzvLqyoGa0r - TLSH:
T10C307EF71097ED4C7A8BAB03AEE70155918DC3886237A760199C272CD8BC1BE7F10990 - Submitted as: lelukudere-luneliwusupoj-tesapug-ledetomuvovap.pdf
- File type: pdf · Size: 38639 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=call%20of%20cthulhu%20character%20sheet%20fillable, https://cdn-cms.f-static.net/uploads/4371524/normal_5f88c732c2364.pdf, https://cdn-cms.f-static.net/uploads/4369926/normal_5f88a41499c0f.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=call%20of%20cthulhu%20character%20sheet%20fillable
- https://cdn-cms.f-static.net/uploads/4371524/normal_5f88c732c2364.pdf
- https://cdn-cms.f-static.net/uploads/4369926/normal_5f88a41499c0f.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f88d408e9174.pdf
- https://cdn-cms.f-static.net/uploads/4369784/normal_5f8858c57c88f.pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f87166eed270.pdf
- https://uploads.strikinglycdn.com/files/d6a8cfc4-c0fa-465c-8ec5-56a16d435b30/mebowig.pdf
- https://uploads.strikinglycdn.com/files/855e0394-01bf-4989-97e1-1e7c1e00dfc0/76142356981.pdf
- https://uploads.strikinglycdn.com/files/9e86331c-a169-466b-aea5-d12220da5bc4/vivesivazoligatixebamifeg.pdf
- https://uploads.strikinglycdn.com/files/27890b97-b013-4d89-981e-abc1f8cfe24b/8984047636.pdf
- https://uploads.strikinglycdn.com/files/fad7a148-8395-413f-9fd2-6a3302307b80/98802349307.pdf
- https://uploads.strikinglycdn.com/files/795784ca-8208-4d45-bebf-98020f163916/15144395567.pdf
- https://uploads.strikinglycdn.com/files/79ea7a1c-c8f1-473e-9d13-78aa91b15d67/lipizajaviwifa.pdf
- https://uploads.strikinglycdn.com/files/69c35f03-c2ba-47b6-8b85-a7528ee888c8/87130255746.pdf
- https://uploads.strikinglycdn.com/files/600d361f-da10-441f-9b04-dbd63bb71232/pepigadafarewapam.pdf
- https://uploads.strikinglycdn.com/files/30810d54-4566-4257-b6ef-f351df41d4d1/xuzejukupokemilimasovo.pdf
- https://site-1036840.mozfiles.com/files/1036840/jimeno.pdf
- https://site-1044201.mozfiles.com/files/1044201/android_phone_master_reset_code.pdf
- https://site-1040681.mozfiles.com/files/1040681/junuvorojivorokefa.pdf
- https://site-1042987.mozfiles.com/files/1042987/67411064111.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/tolujimifiv.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/88bd66a85400a.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279037.pdf
- https://uploads.strikinglycdn.com/files/2afa474f-65b7-4c70-9c2e-39b98fc77efd/99283160574.pdf
- https://uploads.strikinglycdn.com/files/db878f24-7aa7-43a4-81d5-18f8995abaf3/17431686336.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1036840.mozfiles.com
- site-1044201.mozfiles.com
- site-1040681.mozfiles.com
- site-1042987.mozfiles.com
- mojivimimujovo.weebly.com
- boguvetasitob.weebly.com
- fijojonibiw.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report