SUSPICIOUS — vavajuju-potom.pdf
SUSPICIOUS — vavajuju-potom.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 50 detection engines flagged it.
Identification
- SHA-256:
8e33c174c6738f12096314227dc4d5441ac4e97abcd08fafb4f3b649738bdfb0 - SHA-1:
84ce19d825d6d2d24f28035b8fa4235fb05ec689 - MD5:
19fb8a00ccc43a3aaa5fb69fa2ac57da - ssdeep:
768:OgGzpD2prBrwSdPblDbUEvGOjggm9ns6fL9TOL/Nq9PI94k:rGFKprQg2ns+1RPI94k - TLSH:
T1202F6CF310E7ED8C7A879B43AEEA256D948DD3486032A7A04098762DD4BC6BD7E01460 - Submitted as: vavajuju-potom.pdf
- File type: pdf · Size: 35458 bytes
- Verdict: suspicious (35/100)
Detections (1 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=history%20word%20search%20ks3, https://cdn-cms.f-static.net/uploads/4368982/normal_5f8808f68be4c.pdf, https://cdn-cms.f-static.net/uploads/4369334/normal_5f880bd842587.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=history%20word%20search%20ks3
- https://cdn-cms.f-static.net/uploads/4368982/normal_5f8808f68be4c.pdf
- https://cdn-cms.f-static.net/uploads/4369334/normal_5f880bd842587.pdf
- https://cdn-cms.f-static.net/uploads/4374189/normal_5f88fc57d035f.pdf
- https://jimigafekalese.weebly.com/uploads/1/3/1/4/131407537/7831634.pdf
- https://kizekusoviwo.weebly.com/uploads/1/3/1/4/131453028/varipe-bemoruxaxe.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/8600574.pdf
- https://ritibamubube.weebly.com/uploads/1/3/1/4/131437410/2724133.pdf
- https://uploads.strikinglycdn.com/files/ee741dc3-fd60-48fd-a16e-4c1188209870/kijizire.pdf
- https://uploads.strikinglycdn.com/files/d8f23d55-6c8d-428b-9d50-8773bc1c7f86/72271814582.pdf
- https://cdn-cms.f-static.net/uploads/4366304/normal_5f88b2af5021d.pdf
- https://cdn-cms.f-static.net/uploads/4369640/normal_5f87cb5430652.pdf
- https://cdn-cms.f-static.net/uploads/4367004/normal_5f8810c315732.pdf
- https://uploads.strikinglycdn.com/files/080f2521-6f67-4d00-9271-8ee78ba84217/favilufib.pdf
- https://uploads.strikinglycdn.com/files/ff9a1ae2-b913-4c2b-863c-b42dea680a0c/4991570718.pdf
- https://uploads.strikinglycdn.com/files/bba61089-1275-4da9-b15a-57d63a9d5535/20336703103.pdf
- https://uploads.strikinglycdn.com/files/4269b958-543a-498f-b3ef-d9a6c692b677/23501868489.pdf
- https://uploads.strikinglycdn.com/files/26a20aa3-4973-4309-a85e-c872e7c2cdee/73817334257.pdf
- https://cdn.shopify.com/s/files/1/0432/3259/2027/files/97759564784.pdf
- https://cdn.shopify.com/s/files/1/0496/6236/1751/files/foundations_of_government_section_1.pdf
- https://cdn.shopify.com/s/files/1/0484/2940/0221/files/72749230852.pdf
- https://cdn.shopify.com/s/files/1/0481/8432/8344/files/let_us_make_mankind_in_our_image.pdf
- https://cdn.shopify.com/s/files/1/0482/0284/2269/files/santa_monica_college_classes.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- jimigafekalese.weebly.com
- kizekusoviwo.weebly.com
- zesopupejilit.weebly.com
- ritibamubube.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report