SUSPICIOUS — lozepafebobogupoxewireke.pdf
SUSPICIOUS — lozepafebobogupoxewireke.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a2ed646622d619ddc1566ed58b3a86fb38828fc5015839195f39558eac9b3e65 - SHA-1:
a1d9b700cf463bfbc760995c64d23c73e9870486 - MD5:
5bbfaef1a59f5fc53838d242f6392523 - ssdeep:
768:cgGzpDep9icub+wnGYeqtes3kDqvFaBJoq3OIQlfw1CjDG1g4:5GFip9RqEwvFaBJ8fw1CfUg4 - TLSH:
T1A1319EF39197DD8C768BAB0369AA14255049D38D6137A3A044DC7BBED8BC1FE6E00D21 - Submitted as: lozepafebobogupoxewireke.pdf
- File type: pdf · Size: 41653 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=driver+booster+full, https://uploads.strikinglycdn.com/files/d5ec0993-4f57-4e6a-b92e-3e80a1c23a10/80050948743.pdf, https://uploads.strikinglycdn.com/files/e6fe6a27-192e-4543-9bdf-8bd42e913a88/68331401157.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=driver+booster+full
- https://uploads.strikinglycdn.com/files/d5ec0993-4f57-4e6a-b92e-3e80a1c23a10/80050948743.pdf
- https://uploads.strikinglycdn.com/files/e6fe6a27-192e-4543-9bdf-8bd42e913a88/68331401157.pdf
- https://uploads.strikinglycdn.com/files/81ee52d6-047d-41a1-a74e-deb4b28c70a1/28695868820.pdf
- https://uploads.strikinglycdn.com/files/422c626f-93d8-4e27-8ad6-0946084ab7df/sotapazovudivajemojozodik.pdf
- https://site-1036640.mozfiles.com/files/1036640/34565873867.pdf
- https://site-1038558.mozfiles.com/files/1038558/tipitadasumegubekudotuge.pdf
- https://site-1036679.mozfiles.com/files/1036679/20550526836.pdf
- https://site-1048288.mozfiles.com/files/1048288/viretinuxaridofabudosemab.pdf
- https://uploads.strikinglycdn.com/files/6ed2a3be-ff8e-4db3-a1f0-28665af023f7/bajokizebazipitopodorak.pdf
- https://uploads.strikinglycdn.com/files/be26e5e7-cca9-40a4-a510-1a36e4e25adb/guzosisokewefugeb.pdf
- https://cdn.shopify.com/s/files/1/0431/7488/7573/files/oblong_wool_eater_blanket_pattern.pdf
- https://cdn.shopify.com/s/files/1/0482/4986/4353/files/36333411708.pdf
- https://cdn.shopify.com/s/files/1/0440/4389/4934/files/referencing_lecture_notes_apa_6th.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036640.mozfiles.com
- site-1038558.mozfiles.com
- site-1036679.mozfiles.com
- site-1048288.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report