SUSPICIOUS — vasofemino.pdf
SUSPICIOUS — vasofemino.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4fdc77131803c1da6723a61b56c44412081c2c7b485d14791d6898c01df8c74b - SHA-1:
37dbd6d9996efea3e9b6970b3c00967ae5018511 - MD5:
dcf9272707d03c64ff9f956ad810d884 - ssdeep:
1536:QGF0cuYpkfTm5LsUVRTGeFXR/JWb9YwTf:dF0cuYOfy5IUVRCIB/Gie - TLSH:
T1A335AEF32087ED4D768F5F23E9A711A97589D78D6022CB9044497B2CD5BCAAD3F00A60 - Submitted as: vasofemino.pdf
- File type: pdf · Size: 58623 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=skripsi%20hipertensi%202018%20pdf, https://cdn-cms.f-static.net/uploads/4412164/normal_5f94338a55260.pdf, https://cdn-cms.f-static.net/uploads/4368223/normal_5f87b5a87ea02.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=skripsi%20hipertensi%202018%20pdf
- https://cdn-cms.f-static.net/uploads/4412164/normal_5f94338a55260.pdf
- https://cdn-cms.f-static.net/uploads/4368223/normal_5f87b5a87ea02.pdf
- https://cdn-cms.f-static.net/uploads/4393911/normal_5f926e2298cfe.pdf
- https://cdn-cms.f-static.net/uploads/4371261/normal_5f9500b7a034e.pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f8931ee51c20.pdf
- https://cdn-cms.f-static.net/uploads/4367296/normal_5f873d84efc42.pdf
- https://cdn-cms.f-static.net/uploads/4366343/normal_5f89717f0e461.pdf
- https://cdn-cms.f-static.net/uploads/4380539/normal_5f8ac302b4035.pdf
- https://cdn-cms.f-static.net/uploads/4383678/normal_5f9095557ebce.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f8747957f338.pdf
- https://cdn-cms.f-static.net/uploads/4376101/normal_5f8c232c5a6cf.pdf
- https://cdn-cms.f-static.net/uploads/4392660/normal_5f943f887a33d.pdf
- https://cdn.shopify.com/s/files/1/0483/0599/5940/files/matilda_miss_honey_quotes.pdf
- https://cdn.shopify.com/s/files/1/0499/9086/0962/files/marriage_a_la_mode_3.pdf
- https://cdn.shopify.com/s/files/1/0501/7013/4683/files/begopag.pdf
- https://cdn.shopify.com/s/files/1/0488/4565/2133/files/social_media_marketing_analytics.pdf
- https://cdn.shopify.com/s/files/1/0482/2709/0589/files/kisubabebes.pdf
- https://cdn.shopify.com/s/files/1/0502/0840/7724/files/44589118616.pdf
- https://cdn.shopify.com/s/files/1/0266/7927/9812/files/kovukutumalosilakiwaligub.pdf
- https://cdn.shopify.com/s/files/1/0433/0219/1269/files/77383972960.pdf
- https://cdn.shopify.com/s/files/1/0497/5978/1023/files/bsnl_prepaid_recharge_plans_tamilnadu.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/gefup_kimubapodevig_wuxexim_dufati.pdf
- https://tidemipevu.weebly.com/uploads/1/3/0/7/130740592/f47f5.pdf
- https://xexovelez.weebly.com/uploads/1/3/0/8/130813416/bivanuzewagofivopeso.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- vuzevarezevarot.weebly.com
- tidemipevu.weebly.com
- xexovelez.weebly.com
- viweposedijul.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report