SUSPICIOUS — raguteluliwi-luzutovujegesat-tuzigizokeku-tuxene.pdf
SUSPICIOUS — raguteluliwi-luzutovujegesat-tuzigizokeku-tuxene.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f7215465d9ee2c68eae65ac3aecb44300dcadb736b5c5ba0b558ac7e58b07863 - SHA-1:
ac8d5023ffbf952b79d64c74d9f110129a7411cd - MD5:
92ffeac03008679e6f235fba56f64fde - ssdeep:
768:jgGzpDNeZZ5ZDsgd3GO4ZOaQlbXzmt+2i6oE2goFKjgcOX1pD+q8OR1F003:cGFJe35ZDN3GAze+2boEDoFWZ8Kq8OnD - TLSH:
T108329DF3506BED8C37C79B53ADBA255C6049D6883132A36455C87A2CC57C3BD2F20A62 - Submitted as: raguteluliwi-luzutovujegesat-tuzigizokeku-tuxene.pdf
- File type: pdf · Size: 47362 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=problemas%20sumas%20y%20restas%20con%20llevadas%202o%20primaria%20pdf, https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/85f5a0.pdf, https://putojedenavaxo.weebly.com/uploads/1/3/2/6/132683165/d2e568385438b41.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=problemas%20sumas%20y%20restas%20con%20llevadas%202o%20primaria%20pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/85f5a0.pdf
- https://putojedenavaxo.weebly.com/uploads/1/3/2/6/132683165/d2e568385438b41.pdf
- https://fewefemuge.weebly.com/uploads/1/3/4/3/134372507/7047187.pdf
- https://s3.amazonaws.com/tetazino/kagalokipibesofe.pdf
- https://s3.amazonaws.com/pozokimepe/93210248976.pdf
- https://uploads.strikinglycdn.com/files/4f308b87-7100-45b6-9449-43c94040e0e6/25323428594.pdf
- https://uploads.strikinglycdn.com/files/99b51f28-0b77-42e5-8da6-d75cc75ff28e/wubusuxuvakozid.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f87041fb1b86.pdf
- https://cdn-cms.f-static.net/uploads/4368468/normal_5f96c06ab672d.pdf
- https://cdn-cms.f-static.net/uploads/4368500/normal_5f8972cf45322.pdf
- https://s3.amazonaws.com/nezanurugega/toxake.pdf
- https://s3.amazonaws.com/jumedemimo/advanced_accounting_in_tally._erp_9.pdf
- https://s3.amazonaws.com/rebesudanolo/kotojakekutogikepexuwopu.pdf
- https://cdn.shopify.com/s/files/1/0499/4246/2618/files/vibotoxivonax.pdf
- https://cdn.shopify.com/s/files/1/0431/8330/8962/files/33816055252.pdf
- https://cdn.shopify.com/s/files/1/0501/6780/8190/files/gujawoxox.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- mojivimimujovo.weebly.com
- putojedenavaxo.weebly.com
- fewefemuge.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report