SUSPICIOUS — suzeroveguv.pdf
SUSPICIOUS — suzeroveguv.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
5489a9718141f9787d03e4f0e67f1b9facc6f8c98ef4311135ffb1c48d0c8131 - SHA-1:
cb25f07d5ab5d14b6d771ced4bc04c8e50e1c817 - MD5:
0c8399483a2c42e62d52c64ad1bb2ac5 - ssdeep:
1536:FGFk4LjKrI9HpBJzb7VRGNDAa5NUxACSk:YFkejr9J5RMDAa5NUuk - TLSH:
T1B535BFF35067DD8CBA8A6F536EF90059A246C34C2232A560A4ED7A7C84BC6FC6F41431 - Submitted as: suzeroveguv.pdf
- File type: pdf · Size: 58328 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=samurai%20and%20knights%20dbq%20packet, https://uploads.strikinglycdn.com/files/66820ea2-2334-4527-8a05-7fb407fd8bac/jagokodeza.pdf, https://uploads.strikinglycdn.com/files/91126ce2-29ec-4a8d-a3e9-806a286de3b8/pojukemitebejug.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=samurai%20and%20knights%20dbq%20packet
- https://s3.amazonaws.com/xesigeze/c_more_scout_red_dot_for_sale.pdf
- https://uploads.strikinglycdn.com/files/66820ea2-2334-4527-8a05-7fb407fd8bac/jagokodeza.pdf
- https://uploads.strikinglycdn.com/files/91126ce2-29ec-4a8d-a3e9-806a286de3b8/pojukemitebejug.pdf
- https://cdn-cms.f-static.net/uploads/4386606/normal_5fa0e9f926cc8.pdf
- https://s3.amazonaws.com/petuzutemixuvod/cambridge_igcse_mathematics_core_and_extended.pdf
- https://s3.amazonaws.com/jidosatikim/networking_mcq_with_answers.pdf
- https://s3.amazonaws.com/zirojopemup/koxoxadosulovojaxexusewov.pdf
- https://s3.amazonaws.com/leguvefu/emotional_development_in_infants.pdf
- https://s3.amazonaws.com/gifiz/18926721242.pdf
- https://s3.amazonaws.com/tobobowu/jofobamubajejuxamaxuwega.pdf
- https://s3.amazonaws.com/susopuzupure/50809178658.pdf
- https://s3.amazonaws.com/wizuluworafid/noditetadovomumemer.pdf
- https://s3.amazonaws.com/kakef/gexaxoruxerugegipawuxa.pdf
- https://s3.amazonaws.com/memul/sistem_akuntansi_bank_syariah.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report