SUSPICIOUS — liweva.pdf
SUSPICIOUS — liweva.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c719dc127a788c49eab04df33f3db9a137d564820bec61e84b1713cb3b2e18e5 - SHA-1:
50b1f86a7e3a1d1f54c09e5fe5ddc648cd4a4b2c - MD5:
c9a88ef114f30f39cd71b7707f4f1ca7 - ssdeep:
768:UgGzpD4eKHEY9uwkxBrJlTa/Ei7PqH+hceZqSzrn3a/N/luepm05DVGC2nirdHyP:hGFUeKm1qcerzTU3ueIuVphrdA68H - TLSH:
T1BD338DF75597ED4CBB8B9B13ACA611A9208AD74C6133C7A040C8772DC47C6BDBE60950 - Submitted as: liweva.pdf
- File type: pdf · Size: 47617 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=union%20intersection%20of%20sets%20worksheet, https://cdn-cms.f-static.net/uploads/4366630/normal_5f875e738ca29.pdf, https://cdn-cms.f-static.net/uploads/4367624/normal_5f874d263f936.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=union%20intersection%20of%20sets%20worksheet
- https://cdn-cms.f-static.net/uploads/4366630/normal_5f875e738ca29.pdf
- https://cdn-cms.f-static.net/uploads/4367624/normal_5f874d263f936.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87680eb314e.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f86f6149791a.pdf
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f8728cba7770.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f87b7b74733c.pdf
- https://cdn-cms.f-static.net/uploads/4367640/normal_5f87c0f0a8bc2.pdf
- https://cdn-cms.f-static.net/uploads/4366364/normal_5f876c9358fc5.pdf
- https://cdn-cms.f-static.net/uploads/4368731/normal_5f87dda66f661.pdf
- https://kupugaxome.weebly.com/uploads/1/3/0/9/130969415/1e740855884.pdf
- https://biwugina.weebly.com/uploads/1/3/1/1/131163984/fizezaje_remixebuxu_vuvirogizagoful.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/a63fb.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/5473886.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f86f6bbca2dc.pdf
- https://cdn-cms.f-static.net/uploads/4367959/normal_5f87d07415636.pdf
- https://cdn-cms.f-static.net/uploads/4367961/normal_5f879c440d072.pdf
- https://site-1048244.mozfiles.com/files/1048244/50273377084.pdf
- https://site-1038879.mozfiles.com/files/1038879/dokedak.pdf
- https://site-1037899.mozfiles.com/files/1037899/dumopimewativoguretanel.pdf
- https://site-1043908.mozfiles.com/files/1043908/23806218929.pdf
- https://uploads.strikinglycdn.com/files/3ca289d9-bad3-4d18-8ae3-655ba642abec/64152254619.pdf
- https://uploads.strikinglycdn.com/files/9e8e4a58-6144-4153-bfab-9efab0206b38/90797110866.pdf
- https://uploads.strikinglycdn.com/files/daf6b172-e71e-4805-a5d6-adea66b70e35/67238213086.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- kupugaxome.weebly.com
- biwugina.weebly.com
- jatorogerujew.weebly.com
- bedizegoresupa.weebly.com
- site-1048244.mozfiles.com
- site-1038879.mozfiles.com
- site-1037899.mozfiles.com
- site-1043908.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report