SUSPICIOUS — lutake.pdf
SUSPICIOUS — lutake.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
bb77da2476f3eb57949d43079ae4d99d3330bfdd710204ccf9af73203e75c286 - SHA-1:
0939e19a2ee85c5386327ded47f1f7f6d0dc844b - MD5:
c741378c61c66efd72c2da4cb1d24652 - ssdeep:
1536:AGF5QdYL9sI5WzDRq7qgvZsUOFyouwIHZNKJHPdTx7PxtxZe:NF57bVZsUOFGZwpPdE - TLSH:
T19237E1F35597DE9C9A87BB037DBB1429680AC2C91136A720918CB63CD47C37E7E40561 - Submitted as: lutake.pdf
- File type: pdf · Size: 73626 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=self%20worth%20worksheets%20for%20adults%20pdf, https://cdn.shopify.com/s/files/1/0492/6108/4828/files/xexefefamewov.pdf, https://cdn.shopify.com/s/files/1/0504/0373/7750/files/tagewonededinaxufe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=self%20worth%20worksheets%20for%20adults%20pdf
- https://cdn.shopify.com/s/files/1/0492/6108/4828/files/xexefefamewov.pdf
- https://cdn.shopify.com/s/files/1/0504/0373/7750/files/tagewonededinaxufe.pdf
- https://cdn.shopify.com/s/files/1/0266/8308/0877/files/gi_stasis_in_rabbits_recovery.pdf
- https://cdn.shopify.com/s/files/1/0430/0003/7527/files/soggy_doggy_friends_instructions.pdf
- https://cdn.shopify.com/s/files/1/0429/1464/4127/files/26348702919.pdf
- https://cdn.shopify.com/s/files/1/0484/0125/2510/files/4043659402.pdf
- https://s3.amazonaws.com/kavitokolezub/sobagekobebuwuti.pdf
- https://s3.amazonaws.com/zemigiduwagafu/4682054146.pdf
- https://s3.amazonaws.com/kavitokolezub/tisixufutesaninetilip.pdf
- https://s3.amazonaws.com/memul/4555864284.pdf
- https://uploads.strikinglycdn.com/files/416b3ee2-a207-43cf-9549-9422f90ec29c/63258295187.pdf
- https://uploads.strikinglycdn.com/files/8cb43d2d-78a9-4911-9fad-8a03bc922a5e/11362062624.pdf
- https://uploads.strikinglycdn.com/files/8301af79-e8af-4a11-8f97-d784e80e615b/bapedasul.pdf
- https://s3.amazonaws.com/damerirazib/22929984307.pdf
- https://s3.amazonaws.com/gelawiweza/83030373161.pdf
- https://s3.amazonaws.com/jazuravazaguz/ejemplos_de_enlaces_peptidicos_de_aminoacidos.pdf
- https://s3.amazonaws.com/jezaxojipevu/xowojilet.pdf
- https://uploads.strikinglycdn.com/files/4496d5c1-3576-47b7-8ca7-2d0e84ea4d1e/zojelab.pdf
- https://uploads.strikinglycdn.com/files/da45ac2a-e6a2-4e8a-bdc2-a808fef680c0/18249078062.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report