SUSPICIOUS — vemir.pdf
SUSPICIOUS — vemir.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
6f5ef86dc6c7dc81165ae6a0d9145f6bd5e4ee0f9de8dd9a35f3471f73dde266 - SHA-1:
6d2b0e751b4212ca0d80b2213fe9f9ced9273c10 - MD5:
28b9d6f71db029c0fbcefaf144ab8b78 - ssdeep:
1536:YGFse9EaDe1LX7EJSM1FJpelRMgPfaxDPWDH7HlPr3Pi:1Fse9/e1LwJSM1FJpeTA075q - TLSH:
T16A359EF344DBDD4C7986AB83BCBA14A5254AC3492237DB90848CBB6CC4BC67D6E50D60 - Submitted as: vemir.pdf
- File type: pdf · Size: 61337 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=ts5823%20transmitter%20manual, https://uploads.strikinglycdn.com/files/1574c6d9-2fb6-49f6-abc8-81069bae4110/nasifigijojawasogowetaw.pdf, https://uploads.strikinglycdn.com/files/fa51b9a1-7396-4993-924d-2652372d8d80/lamefamirojomewubofam.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=ts5823%20transmitter%20manual
- https://uploads.strikinglycdn.com/files/1574c6d9-2fb6-49f6-abc8-81069bae4110/nasifigijojawasogowetaw.pdf
- https://uploads.strikinglycdn.com/files/fa51b9a1-7396-4993-924d-2652372d8d80/lamefamirojomewubofam.pdf
- https://uploads.strikinglycdn.com/files/c367b0d8-5945-42e5-99e7-97a4b037ad98/14743063256.pdf
- https://uploads.strikinglycdn.com/files/750654b1-4b63-4103-b9df-9d030d42adad/11649467916.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87028c91605.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f86f5068ceb4.pdf
- https://cdn-cms.f-static.net/uploads/4368245/normal_5f8767442dda9.pdf
- https://cdn-cms.f-static.net/uploads/4367624/normal_5f8769bcbce20.pdf
- https://cdn-cms.f-static.net/uploads/4368250/normal_5f876afb072ad.pdf
- https://cdn-cms.f-static.net/uploads/4367624/normal_5f876b0d575af.pdf
- https://uploads.strikinglycdn.com/files/2bf1465b-2405-475f-bc46-24c9f9c56bb6/20334829303.pdf
- https://uploads.strikinglycdn.com/files/afdf9863-b6f4-49b3-8774-1b3fee655aea/zegunemugigesulozerufegaf.pdf
- https://uploads.strikinglycdn.com/files/79255db1-6a0f-41af-9a22-b811f2aa5a8b/81498546037.pdf
- https://site-1037867.mozfiles.com/files/1037867/xasizog.pdf
- https://site-1044154.mozfiles.com/files/1044154/10730240706.pdf
- https://site-1039897.mozfiles.com/files/1039897/ruzudutapibanakaburap.pdf
- https://site-1042106.mozfiles.com/files/1042106/66885630530.pdf
- https://site-1037102.mozfiles.com/files/1037102/fizajusubudevumopojiji.pdf
- https://uploads.strikinglycdn.com/files/66e328cf-32dc-4102-9b6f-caff981cecfe/madod.pdf
- https://uploads.strikinglycdn.com/files/6a075503-ea0e-4c3d-b617-0bd62cf01b1f/17749843662.pdf
- https://uploads.strikinglycdn.com/files/5ba6ed02-f776-4944-9a01-9ab878ac084c/82182273137.pdf
- https://uploads.strikinglycdn.com/files/a3f598ab-ae3a-401d-8319-135b8977581b/80530821965.pdf
- https://uploads.strikinglycdn.com/files/104ac4af-4188-4e95-a7bc-5784e1a50afa/raxep.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1037867.mozfiles.com
- site-1044154.mozfiles.com
- site-1039897.mozfiles.com
- site-1042106.mozfiles.com
- site-1037102.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report