SUSPICIOUS — lunulizuragebesol.pdf
SUSPICIOUS — lunulizuragebesol.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
a74179a00b8dc9f2f8bd9e6bb959937d8498467e8bd4d6de17058226fd67caf4 - SHA-1:
7ea3072f1d33f0f41a9316426451d6448cca5a4d - MD5:
95df8ef2a3436ed88c2036f86a17e628 - ssdeep:
768:+gGzpDGpOyWc4DqmtXzAOEQsz6qBbldVH0NEmDyXB6u4cYXbiPYAQK:7GFqpXvUNEmDyx6u45qYAQK - TLSH:
T19E327CF32097ED4D3A8B9F83AEAB119DA54ED3897027A6600488372CD47C5FDAF10651 - Submitted as: lunulizuragebesol.pdf
- File type: pdf · Size: 44803 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=schrodinger%20wave%20equation%20derivation%20physics%20pdf, https://cdn-cms.f-static.net/uploads/4369777/normal_5f917a815fb5c.pdf, https://cdn-cms.f-static.net/uploads/4366662/normal_5f8f437d49456.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=schrodinger%20wave%20equation%20derivation%20physics%20pdf
- https://cdn-cms.f-static.net/uploads/4369777/normal_5f917a815fb5c.pdf
- https://cdn-cms.f-static.net/uploads/4366662/normal_5f8f437d49456.pdf
- https://cdn-cms.f-static.net/uploads/4389576/normal_5f8f455f89573.pdf
- https://cdn-cms.f-static.net/uploads/4372967/normal_5f8b9b30dced5.pdf
- https://cdn-cms.f-static.net/uploads/4368735/normal_5f8bd99f78e83.pdf
- https://cdn.shopify.com/s/files/1/0482/4852/0866/files/gumufarosorolixe.pdf
- https://cdn.shopify.com/s/files/1/0499/9584/1691/files/vadop.pdf
- https://cdn.shopify.com/s/files/1/0431/8226/0384/files/mulefajede.pdf
- https://uploads.strikinglycdn.com/files/51d9362f-2556-4cd4-a327-54bd4cb9c4c7/43090429823.pdf
- https://uploads.strikinglycdn.com/files/c2760229-b29f-40c6-b033-1da14f086b9b/melatojujilijasapusa.pdf
- https://uploads.strikinglycdn.com/files/0a141334-627c-452b-bb34-97791248ce27/funenopu.pdf
- https://uploads.strikinglycdn.com/files/ef61a067-11e3-4b3d-9146-9f455a5e10a9/35708335353.pdf
- https://cdn.shopify.com/s/files/1/0502/1859/8558/files/molecules_and_compounds_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0429/9200/9379/files/dedamimi.pdf
- https://cdn.shopify.com/s/files/1/0429/9807/1449/files/zexetavulavajas.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/kenimanemud.pdf
- https://cdn.shopify.com/s/files/1/0429/2699/7663/files/exit_path_2.pdf
- https://uploads.strikinglycdn.com/files/c7b22a65-3d4a-40c0-b3bc-2a3d5ba236b4/kaxutokikapakuvojagip.pdf
- https://uploads.strikinglycdn.com/files/6b71c826-2683-435f-ba9e-39b1918be62e/48465498810.pdf
- https://cdn-cms.f-static.net/uploads/4366336/normal_5f89d43298690.pdf
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f88923f55f25.pdf
- https://cdn-cms.f-static.net/uploads/4369777/normal_5f8efa5746640.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report