SUSPICIOUS — duwilof_suxupezomago.pdf
SUSPICIOUS — duwilof_suxupezomago.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d1a2618c8bc4a1c55977d05f0c4d4ae0dec61ecd8bbbaec2fda27ea102adc7b6 - SHA-1:
dfbd81934f0e4366af8c833fc21f443a3b936072 - MD5:
e341e68af041514bf7e9c50d1995ea48 - ssdeep:
1536:2GFWAyNA+kgIJVc/yg+c6l3Ac4/Dep/1n2:PFWACAQoVmy3BAHel12 - TLSH:
T1F035C0F3419BDD4CBF879B43D963009DB18DC788602666945D887B2CD8BC5AEBF20912 - Submitted as: duwilof_suxupezomago.pdf
- File type: pdf · Size: 61227 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=viva%20santa%20cruz%20letra%20pdf, https://uploads.strikinglycdn.com/files/93d835c6-17e1-458c-a60f-d00eea091663/4197191994.pdf, https://uploads.strikinglycdn.com/files/17af3dc2-3737-4193-b5b9-8dfa0585433f/tiluj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=viva%20santa%20cruz%20letra%20pdf
- https://uploads.strikinglycdn.com/files/93d835c6-17e1-458c-a60f-d00eea091663/4197191994.pdf
- https://uploads.strikinglycdn.com/files/17af3dc2-3737-4193-b5b9-8dfa0585433f/tiluj.pdf
- https://uploads.strikinglycdn.com/files/4fe1ba2d-6372-4140-844d-986aa1edd784/total_gym_1000_exercises.pdf
- https://uploads.strikinglycdn.com/files/c3f42d18-c6a0-4804-b3dc-618822efed67/kurepavufomulipawejo.pdf
- https://uploads.strikinglycdn.com/files/7de678f8-2bd2-4f45-8ee1-d47bd4154fa1/joperegefekegus.pdf
- https://uploads.strikinglycdn.com/files/15e74a34-3ecc-4d87-9ca8-a77bb0d6ada3/nifutimarog.pdf
- https://uploads.strikinglycdn.com/files/067ef25a-2889-456e-a504-093e8190ebce/76829272366.pdf
- https://kazofinuso.weebly.com/uploads/1/3/4/3/134369681/berakubaroxi_fojugudepofat_debilugu.pdf
- https://noxetetejiv.weebly.com/uploads/1/3/4/3/134391164/fabivubexatij.pdf
- https://cdn-cms.f-static.net/uploads/4381085/normal_5f8caa557930c.pdf
- https://cdn-cms.f-static.net/uploads/4408355/normal_5f935374be087.pdf
- https://xisubuto.weebly.com/uploads/1/3/1/3/131380177/wevemu_gelilo_novujoj.pdf
- https://xexovelez.weebly.com/uploads/1/3/0/8/130813416/jexelubikegige.pdf
- https://wenadexedodoren.weebly.com/uploads/1/3/4/3/134322255/101d24ce07.pdf
- https://kilutiwoxit.weebly.com/uploads/1/3/1/6/131636983/28f0a18c00fab3f.pdf
- https://kamijiruwidezi.weebly.com/uploads/1/3/4/3/134387945/zawuvatezav_zumunarovekidum_xuwafusa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- kazofinuso.weebly.com
- noxetetejiv.weebly.com
- cdn-cms.f-static.net
- xisubuto.weebly.com
- xexovelez.weebly.com
- wenadexedodoren.weebly.com
- kilutiwoxit.weebly.com
- kamijiruwidezi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report