SUSPICIOUS — lowugamutikipibaler.pdf
SUSPICIOUS — lowugamutikipibaler.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f5403266a6fad77cad14abf0f2f52e395ce3c06428d0069384aafcc87b17cad0 - SHA-1:
81fb7efed35f5e1b50030300ef446ae87d272019 - MD5:
ec8df4cd297783d4378d567e62351424 - ssdeep:
768:RgGzpDWqq1PxblhjSeo8E94QLujeaaQ/KFMfL:iGFa/JblhjTot4qujeC0MfL - TLSH:
T1E62F6CF31497EC8C7A8BAB43AEBA11599487C34862339754589C7B7CD0BC6BD7E00960 - Submitted as: lowugamutikipibaler.pdf
- File type: pdf · Size: 34855 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=avent+electric+steriliser+instruction+manual, https://uploads.strikinglycdn.com/files/4757ec8a-5df7-46d9-a00d-a1ccd737e95d/xuruxarutexalapadewisu.pdf, https://uploads.strikinglycdn.com/files/9e87f48b-4779-48be-9744-2c6e4729ee3b/pidapofasibozozotepanik.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=avent+electric+steriliser+instruction+manual
- https://uploads.strikinglycdn.com/files/4757ec8a-5df7-46d9-a00d-a1ccd737e95d/xuruxarutexalapadewisu.pdf
- https://uploads.strikinglycdn.com/files/9e87f48b-4779-48be-9744-2c6e4729ee3b/pidapofasibozozotepanik.pdf
- https://uploads.strikinglycdn.com/files/8633bb92-c7a2-4607-ba14-de485563ed4d/wopedejilixojawusukidig.pdf
- https://uploads.strikinglycdn.com/files/a784e302-2a88-4513-8bde-eb8fd91220a4/rifigul.pdf
- https://uploads.strikinglycdn.com/files/e29a4b42-7a96-4b41-b9ed-ad24bc5826a1/petiwidopilijimadi.pdf
- https://uploads.strikinglycdn.com/files/6011b455-5f46-4b83-81c2-5c84ebaf5deb/40476401983.pdf
- https://uploads.strikinglycdn.com/files/a7edf515-4f7f-47cb-8839-2c0081fcbe95/nejufitadi.pdf
- https://uploads.strikinglycdn.com/files/a8634fb8-17cc-42a6-a4e7-5ee5f037ead6/7200063205.pdf
- http://files.sascelledesigns.com/uploads/1/3/2/6/132681464/geretedolurimasekami.pdf
- http://files.evolutioneyes.com/uploads/1/3/1/3/131398025/da54c6ebbd4c8.pdf
- http://files.zandertherapeutics.com/uploads/1/3/2/7/132740929/favanaloduzebowupif.pdf
- http://files.microfading.com/uploads/1/3/2/7/132740501/a11638d5c47.pdf
- http://files.discoverychilddevelopmentcenter.com/uploads/1/3/1/1/131164431/690100.pdf
- https://site-1038530.mozfiles.com/files/1038530/vowujototem.pdf
- https://site-1039800.mozfiles.com/files/1039800/69862198500.pdf
- https://site-1039188.mozfiles.com/files/1039188/kuretatovexivivogakotu.pdf
- https://site-1038836.mozfiles.com/files/1038836/81211213584.pdf
- https://site-1036748.mozfiles.com/files/1036748/fibazisitovazulopedigu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- files.sascelledesigns.com
- files.evolutioneyes.com
- files.zandertherapeutics.com
- files.microfading.com
- files.discoverychilddevelopmentcenter.com
- site-1038530.mozfiles.com
- site-1039800.mozfiles.com
- site-1039188.mozfiles.com
- site-1038836.mozfiles.com
- site-1036748.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report