SUSPICIOUS — letuwuzutizobiw.pdf
SUSPICIOUS — letuwuzutizobiw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d5058ec969e7120856d6d3aa3e7d17536a015827a71948a20ff3fdbc01474bb7 - SHA-1:
4c145e4f592ecfe1c59186dda5d8acdef16d8d34 - MD5:
de40b01434d9a09be38d7e8afb656029 - ssdeep:
768:RgGzpDUp0A8zyRYIIS42Dww8xsszY2pMPNUxiEHTSiqmL8dRS9Y:iGFgp03wMzxMPNRamiqmLQRS9Y - TLSH:
T176317CF35097ED4C7A8BAB039DEB009AA589C788A137D7A0549C7B6DD0BC1BE7D10811 - Submitted as: letuwuzutizobiw.pdf
- File type: pdf · Size: 42206 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=cover%20letter%20template%20microsoft%20word, https://site-1043257.mozfiles.com/files/1043257/kusisanawitokinulonivop.pdf, https://site-1042684.mozfiles.com/files/1042684/kizoguwuzudijapizosuvu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=cover%20letter%20template%20microsoft%20word
- https://site-1043257.mozfiles.com/files/1043257/kusisanawitokinulonivop.pdf
- https://site-1042684.mozfiles.com/files/1042684/kizoguwuzudijapizosuvu.pdf
- https://site-1040056.mozfiles.com/files/1040056/nixen.pdf
- https://cdn-cms.f-static.net/uploads/4368242/normal_5f87812b4a647.pdf
- https://cdn-cms.f-static.net/uploads/4367277/normal_5f87a5495ef6b.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f870625ec9eb.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f8731179640b.pdf
- https://cdn-cms.f-static.net/uploads/4367278/normal_5f87b0572a0cf.pdf
- https://site-1044236.mozfiles.com/files/1044236/15932784175.pdf
- https://site-1042729.mozfiles.com/files/1042729/lutogezerojubif.pdf
- https://site-1043755.mozfiles.com/files/1043755/79796928648.pdf
- https://site-1039404.mozfiles.com/files/1039404/bojedipid.pdf
- https://site-1041611.mozfiles.com/files/1041611/nemabafufixizamuzig.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/safado-fodidunixoso.pdf
- https://rivisoni.weebly.com/uploads/1/3/0/7/130739016/bapujim.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/baputedev.pdf
- https://cdn.shopify.com/s/files/1/0481/5028/2393/files/western_union_bugis_junction.pdf
- https://cdn.shopify.com/s/files/1/0478/7978/2566/files/pekufimuguwojonite.pdf
- https://uploads.strikinglycdn.com/files/c6af3b9c-2d65-47d9-be13-f77b8c35a65a/gupada.pdf
- https://uploads.strikinglycdn.com/files/a58681d4-5ecf-4099-809d-5b12432f047e/8575007982.pdf
- https://uploads.strikinglycdn.com/files/aad6ceb7-6ea0-4b98-9be7-b56a08bb6a86/28733896265.pdf
- https://uploads.strikinglycdn.com/files/868319a8-8f24-4930-8adf-bf681cbd785d/waluzatoga.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- site-1043257.mozfiles.com
- site-1042684.mozfiles.com
- site-1040056.mozfiles.com
- cdn-cms.f-static.net
- site-1044236.mozfiles.com
- site-1042729.mozfiles.com
- site-1043755.mozfiles.com
- site-1039404.mozfiles.com
- site-1041611.mozfiles.com
- dimaxafazeza.weebly.com
- rivisoni.weebly.com
- bedizegoresupa.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report