SUSPICIOUS — zomedut_vorafegapes.pdf
SUSPICIOUS — zomedut_vorafegapes.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7823ee90ef1b42a8e955e936c2e1925f826263afbb2c5243560dc4a27008b418 - SHA-1:
40dc50aa97cc82574680af1cba0cd8af9d48370a - MD5:
a6e69f20159d02bbe84736be79f55ef4 - ssdeep:
768:fgGzpDjeMDWekEu9Lj/KYEUrQEhGplGgbeP1189OpR/yeESq:oGFXeMwj/rrboZby+gpR7ESq - TLSH:
T136316CF30167EC8C7BCF6F439DBB11596186C68DA132979054C82B2DC5BC6ED2E40A25 - Submitted as: zomedut_vorafegapes.pdf
- File type: pdf · Size: 42825 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=miguel%20going%20to%20hell%20download, https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/3816443.pdf, https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=miguel%20going%20to%20hell%20download
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/3816443.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf
- https://zoxaminajoge.weebly.com/uploads/1/3/1/6/131637873/26725a8e.pdf
- https://site-1037894.mozfiles.com/files/1037894/dolatidaxeritaraligasowu.pdf
- https://site-1042442.mozfiles.com/files/1042442/40595563439.pdf
- https://site-1043096.mozfiles.com/files/1043096/pinizolubosijuxerid.pdf
- https://site-1038586.mozfiles.com/files/1038586/90882946181.pdf
- https://site-1043882.mozfiles.com/files/1043882/kudugiruwi.pdf
- https://site-1037821.mozfiles.com/files/1037821/fesewelu.pdf
- https://site-1043851.mozfiles.com/files/1043851/70020136677.pdf
- https://site-1043195.mozfiles.com/files/1043195/quest_ce_que_laccumulation_du_capital.pdf
- https://site-1040082.mozfiles.com/files/1040082/nowajiditotiwijufun.pdf
- https://site-1043572.mozfiles.com/files/1043572/7789445786.pdf
- https://uploads.strikinglycdn.com/files/02283d0a-6902-41a3-a647-3c8d7fb69261/26300181233.pdf
- https://uploads.strikinglycdn.com/files/791cd4ac-116b-4e56-86d8-3e1dbb0bbd4a/jamuluwi.pdf
- https://uploads.strikinglycdn.com/files/a10d638d-5dbe-4f6a-9166-1ff26cad985a/67338345480.pdf
- https://uploads.strikinglycdn.com/files/109f0e09-5195-4293-a3bb-52bf9e6fff4c/19207032895.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f8784e5d10a9.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f873706237c9.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/gowijipomunolu_lirogub_loletakimup_rozugofekowe.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rotesojelunemiroto.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- vozunutav.weebly.com
- zoxuzuxebexot.weebly.com
- zoxaminajoge.weebly.com
- site-1037894.mozfiles.com
- site-1042442.mozfiles.com
- site-1043096.mozfiles.com
- site-1038586.mozfiles.com
- site-1043882.mozfiles.com
- site-1037821.mozfiles.com
- site-1043851.mozfiles.com
- site-1043195.mozfiles.com
- site-1040082.mozfiles.com
- site-1043572.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- jatorogerujew.weebly.com
- vuxozajuje.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report