SUSPICIOUS — nulawegategiporozuz.pdf
SUSPICIOUS — nulawegategiporozuz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ba5e5880570da4a5f4f9b71b05f3c013c279c5c68702918321bd33b880dd9116 - SHA-1:
edbdcc3fcb22d9336fb412ba6573a40c7ea3628c - MD5:
6364b41d2a7b8cc82fc6ce15d954a40a - ssdeep:
768:RgGzpDXe4dc7+AZdn92i6uBJXfcL9HsG56EctlwNbtAN5yEryjys:iGFTe4UBWL9HmObtANBryjys - TLSH:
T15D317EF31067EDCC3ACBAF836E9B119DA045C68971229AA055C87A6CD47C2FD7F00961 - Submitted as: nulawegategiporozuz.pdf
- File type: pdf · Size: 40054 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=une%20histoire%20%C3%A0%20quatre%20voix%20ce2, https://site-1037101.mozfiles.com/files/1037101/33730965998.pdf, https://site-1037864.mozfiles.com/files/1037864/75874844436.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=une%20histoire%20%C3%A0%20quatre%20voix%20ce2
- https://site-1037101.mozfiles.com/files/1037101/33730965998.pdf
- https://site-1037864.mozfiles.com/files/1037864/75874844436.pdf
- https://site-1040990.mozfiles.com/files/1040990/kanewasifokujasipidebafi.pdf
- https://cdn.shopify.com/s/files/1/0433/4593/6534/files/mac_tool_box.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f873e260b37f.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f8761086fff5.pdf
- https://cdn.shopify.com/s/files/1/0266/9094/5197/files/sherlock_holmes_brother_and_sister.pdf
- https://cdn.shopify.com/s/files/1/0430/7327/4010/files/fixefejakatowutaz.pdf
- https://cdn.shopify.com/s/files/1/0495/9793/9861/files/sheer_wedding_dress_designers.pdf
- https://cdn.shopify.com/s/files/1/0429/3633/6540/files/99816660777.pdf
- https://cdn.shopify.com/s/files/1/0502/9078/6469/files/86326653083.pdf
- https://cdn.shopify.com/s/files/1/0266/7898/4878/files/youre_getting_old_jokes.pdf
- https://cdn.shopify.com/s/files/1/0481/9782/8760/files/wipamano.pdf
- https://uploads.strikinglycdn.com/files/0b7fc8d8-a5b0-4c81-9c4c-3c18480e9e2b/fujemunudiki.pdf
- https://uploads.strikinglycdn.com/files/9a817a79-cabe-4e60-9b47-3c84462879f9/23722245729.pdf
- https://uploads.strikinglycdn.com/files/6f8f3f3f-31d8-4616-98ab-d0a7853069a6/waguxiropanaja.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037101.mozfiles.com
- site-1037864.mozfiles.com
- site-1040990.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report