SUSPICIOUS — muvuvujulatibor.pdf
SUSPICIOUS — muvuvujulatibor.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c9bc19d147a74af87763089dbe881d69bb7581712acad17fe620cf3d4a8186f1 - SHA-1:
325e8a7f7a3b843044a891fe326c89a3331ee5b6 - MD5:
beacefa6770abea143c7daf627dbb9f4 - ssdeep:
768:NzgGzpD2pRKr0GTAZa4FzycM+H2SBwPUIuiLvsiaOeyJ/UFPk/h8Or6sBzLKVqNm:NMGFqp+o9Cf3Js+/hHBaAPVh2 - TLSH:
T1BF317CF310ABEC4C7A879B13ADA719A96489C789613797A044CC677CC4BC7BD3E10960 - Submitted as: muvuvujulatibor.pdf
- File type: pdf · Size: 41719 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=lspdfr%20042%20_manual_%20install, https://cdn-cms.f-static.net/uploads/4366308/normal_5f88805999b25.pdf, https://cdn-cms.f-static.net/uploads/4365624/normal_5f87605361b17.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=lspdfr%20042%20_manual_%20install
- https://cdn-cms.f-static.net/uploads/4366308/normal_5f88805999b25.pdf
- https://cdn-cms.f-static.net/uploads/4365624/normal_5f87605361b17.pdf
- https://cdn-cms.f-static.net/uploads/4368964/normal_5f878cfc69caa.pdf
- https://cdn-cms.f-static.net/uploads/4369509/normal_5f88c85216227.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f87a6de50278.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f878d694a550.pdf
- https://cdn-cms.f-static.net/uploads/4371498/normal_5f8901af03323.pdf
- https://cdn-cms.f-static.net/uploads/4369498/normal_5f87dec25c177.pdf
- https://cdn-cms.f-static.net/uploads/4369664/normal_5f890bb752ae8.pdf
- https://cdn-cms.f-static.net/uploads/4374177/normal_5f88de68bf1fa.pdf
- https://site-1042840.mozfiles.com/files/1042840/pseudomembranous_colitis_idsa_guidelines.pdf
- https://site-1043377.mozfiles.com/files/1043377/academy_models_catalogue_2020.pdf
- https://site-1038717.mozfiles.com/files/1038717/kakokavew.pdf
- https://uploads.strikinglycdn.com/files/f50d8e14-e69b-427c-98fe-c09decbf3426/fexiga.pdf
- https://uploads.strikinglycdn.com/files/6365de49-69da-466d-9522-069e839c2639/kulefeninupuke.pdf
- https://uploads.strikinglycdn.com/files/7420b460-5606-4de6-b2b3-e35a3078e670/lemixabirujuzujivugulo.pdf
- https://cdn.shopify.com/s/files/1/0432/8855/9782/files/patterns_and_sequences_examples.pdf
- https://cdn.shopify.com/s/files/1/0499/4246/2618/files/solving_quadratic_review_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0483/9270/0062/files/67421801939.pdf
- https://cdn.shopify.com/s/files/1/0496/1861/6473/files/english_worksheets_for_pre_kg.pdf
- https://cdn.shopify.com/s/files/1/0430/5115/5618/files/certificate_of_property_insurance_fillable.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/32e063a95e.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/rimotipa.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/67f7767f9a8dfa.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1042840.mozfiles.com
- site-1043377.mozfiles.com
- site-1038717.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- keniwuki.weebly.com
- juragubiv.weebly.com
- zesopupejilit.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report