SUSPICIOUS — lupovumabusawajizis.pdf
SUSPICIOUS — lupovumabusawajizis.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e3726094ac2a109b536a6b8fd999420f81a5f0cf1a62c7d3eb65038333f19284 - SHA-1:
39199ae763eae43355c356ff39c246d147ab5797 - MD5:
24b2c0a54ffcfdaa01dc656b8b82f36e - ssdeep:
1536:mGFeYLG18TuiS0IryobnXwWcZQATVZdIZ+eVoc2Ji:/FeIuiWr7bngVZDZv++gocF - TLSH:
T1DE349DF35167DD8C7AC79F03AEEA205D505AE7846533A76418882B2CC0BC7BD3E509A1 - Submitted as: lupovumabusawajizis.pdf
- File type: pdf · Size: 53025 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=cardiotonicos+y+antiarritmicos+pdf, https://site-1036840.mozfiles.com/files/1036840/55339297670.pdf, https://site-1036659.mozfiles.com/files/1036659/xokekawomomofewofovov.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=cardiotonicos+y+antiarritmicos+pdf
- https://site-1036840.mozfiles.com/files/1036840/55339297670.pdf
- https://site-1036659.mozfiles.com/files/1036659/xokekawomomofewofovov.pdf
- https://site-1036680.mozfiles.com/files/1036680/17393131054.pdf
- https://site-1037037.mozfiles.com/files/1037037/famikulurezesilakal.pdf
- https://site-1037176.mozfiles.com/files/1037176/wedox.pdf
- https://uploads.strikinglycdn.com/files/853fd179-bf1d-4483-bebe-5d96390db796/jogudepilexotumas.pdf
- https://uploads.strikinglycdn.com/files/61173b66-6c97-4c28-9510-57b2a9225afe/safafojafevo.pdf
- https://uploads.strikinglycdn.com/files/9dbb3b7c-8eac-43fe-8b0e-6e066fdbe154/36265196299.pdf
- https://cdn.shopify.com/s/files/1/0431/0378/1015/files/swarm_robotics_book.pdf
- https://cdn.shopify.com/s/files/1/0433/7565/7125/files/report_writing_findings_and_analysis.pdf
- https://cdn.shopify.com/s/files/1/0439/1007/0440/files/67212113086.pdf
- https://cdn.shopify.com/s/files/1/0437/2201/4871/files/20893610113.pdf
- https://cdn.shopify.com/s/files/1/0428/3547/6636/files/98783492747.pdf
- https://cdn.shopify.com/s/files/1/0436/7450/1273/files/cultural_identity_search_refers_to_the.pdf
- https://cdn.shopify.com/s/files/1/0488/3513/3605/files/gabewax.pdf
- https://cdn.shopify.com/s/files/1/0431/1482/3844/files/miworuxaropi.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/xeniwepisovera.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036840.mozfiles.com
- site-1036659.mozfiles.com
- site-1036680.mozfiles.com
- site-1037037.mozfiles.com
- site-1037176.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report