SUSPICIOUS — mebizuwevog.pdf
SUSPICIOUS — mebizuwevog.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
607fac2a456dcfee2064b5b07aaacdd679fd8fe13561b6def8cc21bdf896153e - SHA-1:
097bf43ce1967aaf88affc2f805084881810f4a7 - MD5:
6c4e1032e9060c2655398ad5b915ef09 - ssdeep:
768:hgGzpDopjPVGnlIYIhzQo/Qf66Jt54y4raDtqUC2uL8FCfL/X7P:SGF8pMOvyqGt0hT/X7P - TLSH:
T11B306CF750D7DD4C7A87AF03A9AA2459518A93886237D760548CAB3CC0BC6BDBF10C61 - Submitted as: mebizuwevog.pdf
- File type: pdf · Size: 37244 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=systems%20of%20linear%20inequalities%20worksheet%20with%20answers, https://cdn.shopify.com/s/files/1/0440/7597/4821/files/4687675245.pdf, https://cdn.shopify.com/s/files/1/0433/2870/0571/files/which_jc_penney_stores_are_closing_in_az.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=systems%20of%20linear%20inequalities%20worksheet%20with%20answers
- https://cdn.shopify.com/s/files/1/0440/7597/4821/files/4687675245.pdf
- https://cdn.shopify.com/s/files/1/0433/2870/0571/files/which_jc_penney_stores_are_closing_in_az.pdf
- https://cdn.shopify.com/s/files/1/0501/8304/5293/files/39313191538.pdf
- https://cdn.shopify.com/s/files/1/0505/4791/6997/files/zee5_premium_account_free_apk.pdf
- https://uploads.strikinglycdn.com/files/5871b668-b625-461e-9cc9-f2a84457c152/69929863801.pdf
- https://uploads.strikinglycdn.com/files/20729542-d139-4691-8080-f783bce05bdd/2007_suzuki_burgman_400_owners_manual.pdf
- https://uploads.strikinglycdn.com/files/ecdcd59f-3bf9-4f7a-a479-cd340693a057/vekegepujagavebemitinu.pdf
- https://uploads.strikinglycdn.com/files/7685d1d0-c70f-4a9f-a905-f2e182e1be18/duwupokuvajeguxezalovu.pdf
- https://uploads.strikinglycdn.com/files/6d322050-b6b1-41e7-b573-db4ebecc03ab/kabik.pdf
- https://folarudivol.weebly.com/uploads/1/3/1/8/131871739/e0825.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/ead64c6e.pdf
- https://bopiwode.weebly.com/uploads/1/3/4/3/134367631/luwidifi.pdf
- https://s3.amazonaws.com/juvuraguvutoxif/costing_engineering.pdf
- https://s3.amazonaws.com/fasanag/wuwox.pdf
- https://uploads.strikinglycdn.com/files/81b90109-39ef-4001-a8dc-0789c6510d18/fokalabizu.pdf
- https://uploads.strikinglycdn.com/files/a941f8a3-006f-4846-b85f-bc728e9d4616/5294602363.pdf
- https://uploads.strikinglycdn.com/files/a300b926-ff46-4a03-914b-102eb06ef355/40664753050.pdf
- https://kesevaze.weebly.com/uploads/1/3/1/3/131383297/vawukanenemomi.pdf
- https://xesaranit.weebly.com/uploads/1/3/2/6/132696194/xakozaduv_vuvowi.pdf
- https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/6262092.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- folarudivol.weebly.com
- jawowigo.weebly.com
- bopiwode.weebly.com
- s3.amazonaws.com
- kesevaze.weebly.com
- xesaranit.weebly.com
- fotejisatowonu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report