SUSPICIOUS — lijunalifukiporukem.pdf
SUSPICIOUS — lijunalifukiporukem.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f039527840783990b06d14f7931ad2c1191eca385e420cc458128b449209a7c2 - SHA-1:
d06c84b95d9d43b5874952d1ae9cd813a29309f7 - MD5:
555040c25e641b7283981c90ad7fe7d9 - ssdeep:
768:MgGzpDKssl6WOIcglTCiM7mRTDh1+c1o9e2Bp+mY0xYgWnSpAA/:JGF27o6M7mRPn+Yo9e2OgtWSpAA/ - TLSH:
T1DE329EF34467ED8C7A8A9B43AEE610AA5199C38C6136A76044CC7B3DD0BC6FD7D40950 - Submitted as: lijunalifukiporukem.pdf
- File type: pdf · Size: 45087 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=how+to+calculate+eta+squared, http://bokov.lennonentertainment.com/uploads/1/3/0/8/130873930/sufegojukezov_rebod_mivilisipefixo.pdf, http://momosesuf.stpetersindy.org/uploads/1/3/1/3/131381428/sexusogewego.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=how+to+calculate+eta+squared
- http://bokov.lennonentertainment.com/uploads/1/3/0/8/130873930/sufegojukezov_rebod_mivilisipefixo.pdf
- http://momosesuf.stpetersindy.org/uploads/1/3/1/3/131381428/sexusogewego.pdf
- http://jedoraj.joewolter.com/uploads/1/3/0/7/130739291/aae0c8a4e.pdf
- http://miteludun.lovingalways.com/uploads/1/3/1/1/131163898/ac28b863b.pdf
- http://files.empowerugandanow.com/uploads/1/3/1/3/131381904/6a115ddec433.pdf
- https://uploads.strikinglycdn.com/files/e816f9a2-c349-4a5a-a45a-5ce8e5f3291f/bamipogitesafekuj.pdf
- https://uploads.strikinglycdn.com/files/0ce2a66f-12e9-42a6-8b1a-b4434f7198a5/rifitovupodolixu.pdf
- https://uploads.strikinglycdn.com/files/e575164a-c704-4c84-9626-8cc530d94a3b/pazepidanarukate.pdf
- https://uploads.strikinglycdn.com/files/bdde17e3-600a-454b-ad56-b9ebc5255707/61926735959.pdf
- https://uploads.strikinglycdn.com/files/a67c86b7-946a-4d41-b299-ceab2e0d1572/xixakiwarimimapalelixil.pdf
- https://cdn.shopify.com/s/files/1/0484/4132/7774/files/porra_del_america_letra.pdf
- https://cdn.shopify.com/s/files/1/0435/0928/5024/files/attic_ladder_home_depot_canada.pdf
- https://cdn.shopify.com/s/files/1/0481/7793/8583/files/beth_total_drama_personality.pdf
- https://cdn.shopify.com/s/files/1/0429/1677/4054/files/farming_simulator_17_apk_download_for_pc.pdf
- https://cdn.shopify.com/s/files/1/0432/0634/4868/files/15457711084.pdf
- https://site-1039173.mozfiles.com/files/1039173/93232368263.pdf
- https://site-1036871.mozfiles.com/files/1036871/11814731871.pdf
- https://site-1036779.mozfiles.com/files/1036779/lekipoxufuvenek.pdf
- https://site-1036939.mozfiles.com/files/1036939/90342339176.pdf
- https://site-1041395.mozfiles.com/files/1041395/75748930688.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- bokov.lennonentertainment.com
- momosesuf.stpetersindy.org
- jedoraj.joewolter.com
- miteludun.lovingalways.com
- files.empowerugandanow.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1039173.mozfiles.com
- site-1036871.mozfiles.com
- site-1036779.mozfiles.com
- site-1036939.mozfiles.com
- site-1041395.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report