SUSPICIOUS — lafaxarun.pdf
SUSPICIOUS — lafaxarun.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f31edd4ff6d454f59345406640a1712f8355a3a5b995a74268c27a22d7ba627e - SHA-1:
563d04f2ba7f2c448ce7f64eb800a05667c0d811 - MD5:
1eea7f427c80b5272d6cb79e15cc4c58 - ssdeep:
768:IgGzpDQKqc1LNedNBhXFgkyvKiOqkrk+V1OgTEy6QXE7rY1c89W:FGFMBlBLgkySiOHrXV1O0EQXk89W - TLSH:
T119316DF3009BED4C3A875B43ACBA115AA58BD38C6137A760599C773CD4AC6ED6F10860 - Submitted as: lafaxarun.pdf
- File type: pdf · Size: 41548 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=netscout%20aircheck%20g2%20user%20manual, https://cdn.shopify.com/s/files/1/0488/0623/2229/files/nazefugegubamixa.pdf, https://cdn.shopify.com/s/files/1/0501/7953/9134/files/94785407928.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=netscout%20aircheck%20g2%20user%20manual
- https://cdn.shopify.com/s/files/1/0488/0623/2229/files/nazefugegubamixa.pdf
- https://cdn.shopify.com/s/files/1/0501/7953/9134/files/94785407928.pdf
- https://cdn.shopify.com/s/files/1/0498/1319/2859/files/52126614493.pdf
- https://cdn.shopify.com/s/files/1/0481/5916/2521/files/democracy_and_education_dewey.pdf
- https://uploads.strikinglycdn.com/files/6b1b3bb1-e6c3-4ab6-9df9-d3689be8455d/wevixibanowow.pdf
- https://uploads.strikinglycdn.com/files/63644cd9-9e56-400d-a24d-a6c2cdd40cc7/buganajejakelebusixojip.pdf
- https://s3.amazonaws.com/rubidokezive/69346516141.pdf
- https://s3.amazonaws.com/regegozumekoza/hydraulic_valve_actuators.pdf
- https://s3.amazonaws.com/henghuili-files2/carillas_de_resina_indirectas.pdf
- https://s3.amazonaws.com/xanebavifamopez/kowomepejugovajuwikuzuwan.pdf
- https://s3.amazonaws.com/julaxel/wapiwinifiguluj.pdf
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/5fb94e7.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf
- https://fanawilixu.weebly.com/uploads/1/3/1/4/131408209/297455.pdf
- https://wosezobar.weebly.com/uploads/1/3/1/8/131856012/6711581.pdf
- https://jarapitoxedomel.weebly.com/uploads/1/3/1/4/131437170/9928676.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/dolunabijosim.pdf
- https://ximazula.weebly.com/uploads/1/3/0/7/130738777/4360936.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/fatutikagile.pdf
- https://zilavexeredora.weebly.com/uploads/1/3/0/8/130874610/1957136.pdf
- https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/6287688.pdf
- https://s3.amazonaws.com/bevarolimesale/authoring_books_and_technical_documents_with_r_markdown.pdf
- https://s3.amazonaws.com/leguvefu/bofijatakosabozo.pdf
- https://s3.amazonaws.com/kavitokolezub/63860964146.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- digonowokeke.weebly.com
- zoxuzuxebexot.weebly.com
- fanawilixu.weebly.com
- wosezobar.weebly.com
- jarapitoxedomel.weebly.com
- xojisige.weebly.com
- ximazula.weebly.com
- besiwalufeg.weebly.com
- zilavexeredora.weebly.com
- moxitasa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report