SUSPICIOUS — makivivivugodelukuvof.pdf
SUSPICIOUS — makivivivugodelukuvof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f1b6a15447c4f8d38e5eeba063cb72ce3bffed0d299c965199852029cf7b7945 - SHA-1:
699152021d25ec91539b8a6af5b09ecce154c0e9 - MD5:
6499373cc4be3b57f955138cdcaa347a - ssdeep:
768:kgGzpDypVSTPyyg49RgeJT9xRIlRaf4b2QEw8zB+Z2CN2SUg:RGF+pVSltnZb3Inaf4KQvOAZxN2SUg - TLSH:
T168308DF3106BDC8C7A47AB13A9AA14692149D78D613797B0159C3B2DC4FCABDBE00C21 - Submitted as: makivivivugodelukuvof.pdf
- File type: pdf · Size: 36750 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=assertividade+na+adolescencia+pdf, https://site-1048265.mozfiles.com/files/1048265/76074614057.pdf, https://site-1039330.mozfiles.com/files/1039330/xekoralekebanoneve.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=assertividade+na+adolescencia+pdf
- https://site-1048265.mozfiles.com/files/1048265/76074614057.pdf
- https://site-1039330.mozfiles.com/files/1039330/xekoralekebanoneve.pdf
- https://site-1036851.mozfiles.com/files/1036851/xerutisupezulenalal.pdf
- https://site-1038478.mozfiles.com/files/1038478/tonofomigavalatedo.pdf
- https://site-1043660.mozfiles.com/files/1043660/46594419582.pdf
- https://uploads.strikinglycdn.com/files/c9f2935a-300f-4eeb-86f4-c0105888a866/7715540073.pdf
- https://uploads.strikinglycdn.com/files/5caf091d-f6ab-41c5-9f2b-c533fe9acea1/99297687365.pdf
- https://uploads.strikinglycdn.com/files/861e2bb9-9fc2-4189-81e6-10f39c7df28f/wilok.pdf
- https://uploads.strikinglycdn.com/files/f25feb60-5113-4ae3-8ccd-fdb8453e0ce5/niloxumepepaba.pdf
- https://uploads.strikinglycdn.com/files/b8d26d28-5234-4291-9d4a-86cb9e3d1f1d/bewapatovuvubuzujam.pdf
- https://uploads.strikinglycdn.com/files/14292136-49e9-40bb-a910-d9118a64d03f/vixojimivejezoz.pdf
- https://uploads.strikinglycdn.com/files/10d2ffe1-4ec5-45e9-aacc-a3090a38ae95/15867276349.pdf
- https://cdn.shopify.com/s/files/1/0484/6573/9930/files/multiplicative_inverse_property_of_zero.pdf
- https://cdn.shopify.com/s/files/1/0495/9895/5684/files/31484039109.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1048265.mozfiles.com
- site-1039330.mozfiles.com
- site-1036851.mozfiles.com
- site-1038478.mozfiles.com
- site-1043660.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report