SUSPICIOUS — lalenijenufuvefama.pdf
SUSPICIOUS — lalenijenufuvefama.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
b81eff128b0ad0ba42d47bd759395fb82e447ee149311a0296eeaab033d291f2 - SHA-1:
45e3e430c3d98957d6492d917e41e92a4d64e970 - MD5:
e65bff640c87efd89ffbd2c231f393df - ssdeep:
768:ZgGzpDep2BP3INixA4DcUAFdYvTyDMuoAVe1:aGFipOllvTvAVe1 - TLSH:
T1CB318DF314A7ED8C798B9B03AEB72559614AD74C723BD7A04488376DC4BC2BD6E00921 - Submitted as: lalenijenufuvefama.pdf
- File type: pdf · Size: 40031 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=new%20hampshire%20vodka, https://uploads.strikinglycdn.com/files/a93d44f1-240c-445f-82db-9d45110984a6/bexazuwit.pdf, https://uploads.strikinglycdn.com/files/7ab52867-5d1f-49e2-9901-4ceda7d7b93c/24329006442.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=new%20hampshire%20vodka
- https://uploads.strikinglycdn.com/files/a93d44f1-240c-445f-82db-9d45110984a6/bexazuwit.pdf
- https://uploads.strikinglycdn.com/files/7ab52867-5d1f-49e2-9901-4ceda7d7b93c/24329006442.pdf
- https://uploads.strikinglycdn.com/files/337b6083-dd63-4401-9887-2a8cd3dccf11/sharp_aquos_lc_32d43u.pdf
- https://uploads.strikinglycdn.com/files/af12d7df-4b81-42ca-b057-287a3eab6157/lefefujufiteg.pdf
- https://uploads.strikinglycdn.com/files/10c4bbdc-7f3e-4651-91e9-46fe10930986/guvexuj.pdf
- https://uploads.strikinglycdn.com/files/12594b57-59b3-4cfc-8585-fa65e38e9400/wobuvejerelujuzixaxeduj.pdf
- https://uploads.strikinglycdn.com/files/54f63221-3117-45b8-a059-6a4ac74e6060/20664393122.pdf
- https://uploads.strikinglycdn.com/files/1007935a-44f1-4949-a55f-34841e389c6f/state_management_in_asp._net.pdf
- https://uploads.strikinglycdn.com/files/f59a8a5e-5d07-4fac-9a92-d881822b8aa4/aahd2-_hy_drivers.pdf
- https://uploads.strikinglycdn.com/files/c5cc4c93-2dfc-47c9-bb17-022a3525df10/pokaperawofuxonaxijutu.pdf
- https://uploads.strikinglycdn.com/files/623ad56a-d4e4-42be-ab1e-00682b6dc59b/96088018958.pdf
- https://cdn.shopify.com/s/files/1/0497/5172/0090/files/sawgrass_movies_saturday.pdf
- https://cdn.shopify.com/s/files/1/0503/8650/1806/files/napkin_rings_ebay_australia.pdf
- https://cdn.shopify.com/s/files/1/0431/0233/9232/files/fundamentals_of_management_robbins.pdf
- https://s3.amazonaws.com/gavexilatuvitaz/book_reader_download.pdf
- https://s3.amazonaws.com/fasanag/kumpulan_cerita_dalam_bahasa_inggris.pdf
- https://s3.amazonaws.com/kavitokolezub/cours_d_anglais_debutant.pdf
- https://s3.amazonaws.com/subud/ferujonebuxasufe.pdf
- https://s3.amazonaws.com/leguvefu/turixobetuni.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report