SUSPICIOUS — ligotiwu-zafekexagitoreg.pdf
SUSPICIOUS — ligotiwu-zafekexagitoreg.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d37c469aca89c98aebd1facb9036a54d6754957a442ab1b9e8bb3f030f678bff - SHA-1:
d5d90171ec7502cf5bae7a09361875cb7372c693 - MD5:
834f1138ea61f60b53eafe8ea56ac822 - ssdeep:
768:wgGzpDlpXB6XH/FlqVDkC7+0Qpufm/EPTRjDvqEzAgMCo8EUyDBjXn2okn:dGFJpqliE0jNljDSEBxE9DBbngn - TLSH:
T1CB329EF300A7EE4C6A8B6BC769F605492149D38C3227936008E8B76DD97C1BDBF10961 - Submitted as: ligotiwu-zafekexagitoreg.pdf
- File type: pdf · Size: 43589 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=automatizacion%20industrial%20definicion%20pdf, https://uploads.strikinglycdn.com/files/e1210bf1-884c-4b29-b66e-983356e1e48c/14355988006.pdf, https://uploads.strikinglycdn.com/files/ca74c0a7-0c04-480f-bc0c-a39f03f48560/78496080403.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=automatizacion%20industrial%20definicion%20pdf
- https://uploads.strikinglycdn.com/files/e1210bf1-884c-4b29-b66e-983356e1e48c/14355988006.pdf
- https://uploads.strikinglycdn.com/files/ca74c0a7-0c04-480f-bc0c-a39f03f48560/78496080403.pdf
- https://uploads.strikinglycdn.com/files/63bac344-3162-4550-9b86-fe19be3e8f8c/wagakikagebugowexorusove.pdf
- https://uploads.strikinglycdn.com/files/5233f83e-d0d3-4609-937f-7c443457f0f6/55327523584.pdf
- https://cdn.shopify.com/s/files/1/0438/0937/4368/files/nevekokejokimebujig.pdf
- https://cdn.shopify.com/s/files/1/0481/9995/8680/files/robevozasiwisuf.pdf
- https://uploads.strikinglycdn.com/files/73398e8c-71c6-4816-a54d-d0fdcd64b774/11641304608.pdf
- https://uploads.strikinglycdn.com/files/a99d0699-6821-4372-a201-84f3a46cc873/90343443685.pdf
- https://s3.amazonaws.com/sedimeraxufi/93960503161.pdf
- https://s3.amazonaws.com/xazarujokemus/amoeboid_tapetum.pdf
- https://s3.amazonaws.com/jasadavebaga/kufusilunamaxatuxil.pdf
- https://s3.amazonaws.com/dazifozixawus/us_address_abbreviations.pdf
- https://s3.amazonaws.com/liwafo/sakarata.pdf
- https://uploads.strikinglycdn.com/files/e54d96e9-f7d5-4dc9-a89c-59e0452b4b72/fan-tastic_vent_cover_installation_instructions.pdf
- https://uploads.strikinglycdn.com/files/2abccea6-387c-45f3-929c-ed31de3df058/84709812925.pdf
- https://uploads.strikinglycdn.com/files/05809e9f-719c-4b38-ae14-e91c8f7b1b4f/wajekojezitidujafewir.pdf
- https://uploads.strikinglycdn.com/files/41a35450-0909-411b-a840-c3ffcbc02589/38115015723.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report