SUSPICIOUS — visezoku.pdf
SUSPICIOUS — visezoku.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
13e302d1c7509284d5766c15e9d817c9bc62714cf9b355a5e30ec3476433a35c - SHA-1:
41e8f1b91ed202c8327ee798cd1104dd69066ddf - MD5:
8645f106777b22444448a2a65cf6fc8a - ssdeep:
768:lgGzpDwi3kgBOKPShOweoB2gZsC/WMF/qfseIicJ1DSrXyDrfzm:2GFEa4KahOw92gZr/WYyfseIicJlLPzm - TLSH:
T19C319EF365A7EC8C7A825B036DB61156A58BC30C9233D66458D8772CC4BC6BD6F00972 - Submitted as: visezoku.pdf
- File type: pdf · Size: 40914 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=the+intelligent+investor+mobi+download, http://files.malfinisproductions.com/uploads/1/3/0/7/130775759/gibevenaba.pdf, http://files.iditarod100.org/uploads/1/3/0/7/130775320/3886072.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=the+intelligent+investor+mobi+download
- http://files.malfinisproductions.com/uploads/1/3/0/7/130775759/gibevenaba.pdf
- http://files.iditarod100.org/uploads/1/3/0/7/130775320/3886072.pdf
- http://files.herewegrowagainsale.com/uploads/1/3/2/6/132681746/d7a8395e5e25c.pdf
- http://wuboledi.locallyhandbuilt.com/uploads/1/3/1/6/131637308/7695306.pdf
- https://site-1036748.mozfiles.com/files/1036748/93899758119.pdf
- http://files.allisoncamerongray.com/uploads/1/3/0/9/130969172/fegebibadivak.pdf
- http://gojofugiw.wizardofwonders.gallery/uploads/1/3/2/6/132681670/bapefug.pdf
- http://files.parkviewclc.com/uploads/1/3/1/3/131378837/5eb3fb3edf04b1.pdf
- http://besot.engagingnh.org/uploads/1/3/1/4/131455069/kekijogawatugifezej.pdf
- http://files.jackiespencerbeatleguide.com/uploads/1/3/1/3/131380601/lokarefoduk.pdf
- https://site-1037022.mozfiles.com/files/1037022/52387374472.pdf
- https://site-1039563.mozfiles.com/files/1039563/mijuzutetad.pdf
- https://site-1039544.mozfiles.com/files/1039544/88315171752.pdf
- https://site-1037189.mozfiles.com/files/1037189/tukelafided.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- files.malfinisproductions.com
- files.iditarod100.org
- files.herewegrowagainsale.com
- wuboledi.locallyhandbuilt.com
- site-1036748.mozfiles.com
- files.allisoncamerongray.com
- files.parkviewclc.com
- besot.engagingnh.org
- files.jackiespencerbeatleguide.com
- site-1037022.mozfiles.com
- site-1039563.mozfiles.com
- site-1039544.mozfiles.com
- site-1037189.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
- gojofugiw.wizardofwonders.gallery
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report