SUSPICIOUS — vurep.pdf
SUSPICIOUS — vurep.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
595dde211a1700f64ae239fe31228bf46af1dd56bf3842b9b411e0731417945e - SHA-1:
2287b632f976f92f218eddaf944b4a3df571dcdf - MD5:
914d65737b19828975d926566b3cde78 - ssdeep:
768:PgGzpDceZ8XnE6acz5VqoS073zaKUg4BSOVXhnIImOIKVXfF7song8sdvTh/1RwY:4GFIeKg9hBXfxpnDsdvThtR3zVwM - TLSH:
T124338DF358A7DD8D7AC6AB53ACB7211A508BDB886132A650448C772CD47C6BDBE10860 - Submitted as: vurep.pdf
- File type: pdf · Size: 47825 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=msp%20hack%20no%20survey, https://cdn.shopify.com/s/files/1/0431/6525/3792/files/bomenanisosixowulo.pdf, https://cdn.shopify.com/s/files/1/0496/6980/0089/files/43820178982.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=msp%20hack%20no%20survey
- https://cdn.shopify.com/s/files/1/0431/6525/3792/files/bomenanisosixowulo.pdf
- https://cdn.shopify.com/s/files/1/0496/6980/0089/files/43820178982.pdf
- https://cdn.shopify.com/s/files/1/0484/0665/9240/files/hcf_and_lcm_worksheets_grade_4.pdf
- https://cdn.shopify.com/s/files/1/0497/5135/9642/files/el_gran_yo_soy_acordes.pdf
- https://cdn.shopify.com/s/files/1/0483/6835/3431/files/6443040758.pdf
- https://cdn-cms.f-static.net/uploads/4375075/normal_5f8bb0f518884.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f86fc5e6d2cb.pdf
- https://cdn-cms.f-static.net/uploads/4368770/normal_5f8d6faab80c1.pdf
- https://cdn-cms.f-static.net/uploads/4387419/normal_5f8d65545b8b8.pdf
- https://cdn.shopify.com/s/files/1/0501/0613/8787/files/dupray_steam_cleaner_instructions.pdf
- https://cdn.shopify.com/s/files/1/0495/6572/8920/files/34137595223.pdf
- https://cdn.shopify.com/s/files/1/0499/6680/9241/files/car_wash_hose_attachment_brush.pdf
- https://cdn.shopify.com/s/files/1/0481/5916/2521/files/13519238423.pdf
- https://cdn.shopify.com/s/files/1/0440/6909/3541/files/68232176349.pdf
- https://cdn.shopify.com/s/files/1/0432/6627/7534/files/7781669452.pdf
- https://cdn.shopify.com/s/files/1/0483/1503/9908/files/paper_towns_free_full_movie.pdf
- https://cdn.shopify.com/s/files/1/0484/0878/9150/files/prejuicios_estereotipos_y_estigmas.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/40ddfa4d7f4e3e.pdf
- https://mijisurux.weebly.com/uploads/1/3/1/0/131070147/ximimebasoril-tabimotifonud-midaririkem.pdf
- https://finazodaxuvoj.weebly.com/uploads/1/3/2/6/132682535/bepefu.pdf
- https://runebipunozup.weebly.com/uploads/1/3/1/4/131406604/kinojupebul-fofedonabilu-tudaj.pdf
- https://wefejakero.weebly.com/uploads/1/3/0/8/130814310/46fc7defa5a7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- mogilifus.weebly.com
- mijisurux.weebly.com
- finazodaxuvoj.weebly.com
- runebipunozup.weebly.com
- wefejakero.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report