SUSPICIOUS — vesitomig.pdf
SUSPICIOUS — vesitomig.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
244b1996506e013613b839698801a37ee40a340863b3c77487250e4249f1b69d - SHA-1:
d421c788c1cfc7dc2925696154cca39646d55647 - MD5:
32ff69a18d0dcecf90038c8d8aaf463a - ssdeep:
768:fgGzpDxpYZvckSbIanKpbIzmYxupBMYvpY1f9zhF8yaj6WziD1FGSyLRsy+:oGFdp8bmnxucYwf6j6WiD1czRsy+ - TLSH:
T1B9329DF350A3EC8D7A8BAB475CEB10A95149D748A17793A058CC2B5DC07C3BD6F14950 - Submitted as: vesitomig.pdf
- File type: pdf · Size: 47235 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ever%20be%20aaron%20shust, https://uploads.strikinglycdn.com/files/13298066-4fbb-4ee3-ba05-ea90c71eef48/36238246415.pdf, https://uploads.strikinglycdn.com/files/b6778dce-c0d5-4ca0-bde4-6e7dd679d7b8/foputis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ever%20be%20aaron%20shust
- https://uploads.strikinglycdn.com/files/13298066-4fbb-4ee3-ba05-ea90c71eef48/36238246415.pdf
- https://uploads.strikinglycdn.com/files/b6778dce-c0d5-4ca0-bde4-6e7dd679d7b8/foputis.pdf
- https://uploads.strikinglycdn.com/files/89c659f6-65bd-41ff-86d5-805fba0773d5/ropobasosa.pdf
- https://uploads.strikinglycdn.com/files/eb78d49f-ae4f-4db4-b5f2-f665977af6a9/32190977174.pdf
- https://site-1038299.mozfiles.com/files/1038299/funatimemekibasozu.pdf
- https://site-1038429.mozfiles.com/files/1038429/22009376185.pdf
- https://cdn.shopify.com/s/files/1/0493/1626/6150/files/air_force_position_paper_example.pdf
- https://cdn.shopify.com/s/files/1/0429/9603/9833/files/le_pacte_dactionnaire_en_droit_ohada.pdf
- https://cdn.shopify.com/s/files/1/0463/3070/8129/files/35535917098.pdf
- https://cdn.shopify.com/s/files/1/0480/6793/6420/files/taotronics_laser_barcode_scanner_setup.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/xananovetivagizaxa.pdf
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/6839400.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/6069273.pdf
- https://uploads.strikinglycdn.com/files/9a4d8d82-fe39-4b26-b39f-32eb2b7a98fc/sawipesegaponikelanolewo.pdf
- https://uploads.strikinglycdn.com/files/92f6eb9d-c702-4833-8701-1765e97b2845/43759982051.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f8884d277730.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f87276f0b1be.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1038299.mozfiles.com
- site-1038429.mozfiles.com
- cdn.shopify.com
- rimesozarabef.weebly.com
- wefamojugibe.weebly.com
- bedizegoresupa.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report