SUSPICIOUS — vanisulo.pdf
SUSPICIOUS — vanisulo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
35b77097f0117b238427c40d09d797cbeafda965ef02d49021c4cd95f2c11b61 - SHA-1:
40393f8eccf87962cc392d0ce791024d0039d6f5 - MD5:
6aea6521324f5301a6aa1da01ff36352 - ssdeep:
768:SgGzpDylWNnqnMYqNNcca8gx9v99MbjrtICCpJSV1epkI4FX90R:PGFuwBmbHYlICCpJ+e5mX90R - TLSH:
T1CD328CF35097DD4C3AC3EB136EDA296CA149D2896176EBA044CC2B2DC47C3AD7E40A50 - Submitted as: vanisulo.pdf
- File type: pdf · Size: 44367 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=carcinoma%20basocelular%20pronostico%20pdf, https://uploads.strikinglycdn.com/files/19bbd5d0-87f3-4c17-a530-d88a1e4b2d33/vibukazaritavapuvenuzex.pdf, https://uploads.strikinglycdn.com/files/807e7d57-b21b-4382-b290-f7ac3f7be375/98669213170.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=carcinoma%20basocelular%20pronostico%20pdf
- https://uploads.strikinglycdn.com/files/19bbd5d0-87f3-4c17-a530-d88a1e4b2d33/vibukazaritavapuvenuzex.pdf
- https://uploads.strikinglycdn.com/files/807e7d57-b21b-4382-b290-f7ac3f7be375/98669213170.pdf
- https://uploads.strikinglycdn.com/files/2a855acb-f6e0-418c-91e5-f539844dd6f1/mega_man_10_rom_download.pdf
- https://uploads.strikinglycdn.com/files/a57866e9-6b9b-44a2-a8f4-39158141c7e7/ledomexevugivurinu.pdf
- https://uploads.strikinglycdn.com/files/d6e4450e-be7e-46c2-9b39-8e9b03594f19/zebifofamarizalok.pdf
- https://uploads.strikinglycdn.com/files/6ebee75c-b127-474e-8006-a938b2d3929a/8742808089.pdf
- https://uploads.strikinglycdn.com/files/ef2d9e9b-4097-483e-84db-be71666ed6da/google_developer_android_training.pdf
- https://s3.amazonaws.com/vukusa/31407061751.pdf
- https://s3.amazonaws.com/kavitokolezub/97180821419.pdf
- https://s3.amazonaws.com/bubodeliza/puzaximu.pdf
- https://uploads.strikinglycdn.com/files/f4584283-e2a1-42cf-9bcf-18cb768ad51e/printable_tarot_cards_with_meanings.pdf
- https://uploads.strikinglycdn.com/files/3ad7e693-76f3-4d47-8cc7-b926206f3415/wipeno.pdf
- https://cdn.shopify.com/s/files/1/0492/3742/6342/files/wiripafaleberozonu.pdf
- https://cdn.shopify.com/s/files/1/0431/6001/0912/files/rock_lobster_family_guy_chords.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f8fc58031835.pdf
- https://cdn-cms.f-static.net/uploads/4365608/normal_5f8aec47db14b.pdf
- https://cdn-cms.f-static.net/uploads/4369511/normal_5f899904e8133.pdf
- https://cdn-cms.f-static.net/uploads/4393019/normal_5f9467f7ea0d0.pdf
- https://cdn-cms.f-static.net/uploads/4369524/normal_5f901203d7ca7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report