SUSPICIOUS — vebokupameseroru.pdf
SUSPICIOUS — vebokupameseroru.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
8fa6a1e424832bc788b65345e70c554b8ad6c0bb571ae21ac530b7b2a402ad25 - SHA-1:
6d49b77c6de409286f2f561005e2e8b43c35e444 - MD5:
94699daa8511a02266860f65ea225ddb - ssdeep:
1536:+GF6p8s2Fcz1SRRbspK356DFbABmbmyvTFKY8sycz:nF6pP2FBRyKpKBABHyvTFKY8u - TLSH:
T12936D0F354A7DC4C7A87AF837DB626996448C2C86227D30014986B5DD4BC6FDBF10A20 - Submitted as: vebokupameseroru.pdf
- File type: pdf · Size: 66231 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=edius%20kurgu%20program%C4%B1%20indir%20gezginler, https://cdn.shopify.com/s/files/1/0464/7603/4198/files/vowaruwurazovidomuf.pdf, https://cdn.shopify.com/s/files/1/0432/4435/5739/files/86334851120.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=edius%20kurgu%20program%C4%B1%20indir%20gezginler
- https://cdn.shopify.com/s/files/1/0464/7603/4198/files/vowaruwurazovidomuf.pdf
- https://cdn.shopify.com/s/files/1/0432/4435/5739/files/86334851120.pdf
- https://cdn.shopify.com/s/files/1/0481/4884/0599/files/midland_g7_radio_manual.pdf
- https://cdn.shopify.com/s/files/1/0436/2108/9444/files/maine_maritime_football.pdf
- https://cdn.shopify.com/s/files/1/0497/5201/5002/files/88324431737.pdf
- https://cdn.shopify.com/s/files/1/0482/1896/4122/files/89679597432.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f86f9cc3bfb0.pdf
- https://cdn-cms.f-static.net/uploads/4366633/normal_5f873b1f36a8b.pdf
- https://uploads.strikinglycdn.com/files/15befbf9-6798-4c52-b114-8bc9dc580775/44082323206.pdf
- https://uploads.strikinglycdn.com/files/1ffdc38b-acee-4c24-b536-65e8c6af5199/govenujanotitutagexukuves.pdf
- https://uploads.strikinglycdn.com/files/3b2df484-757e-413a-b703-04bd4c180546/46468587044.pdf
- https://uploads.strikinglycdn.com/files/aeed6cfb-7571-41fa-8594-5c4a4e56f866/32039388169.pdf
- https://uploads.strikinglycdn.com/files/2d1563c7-9cc2-4f3b-a152-4ef07a4f6a96/88819123206.pdf
- https://uploads.strikinglycdn.com/files/2185280b-2594-4b4c-aee4-1a5fb3f9d6e2/82010228843.pdf
- https://uploads.strikinglycdn.com/files/9b0831c4-728a-4210-a26a-b45f680476c4/16242869355.pdf
- https://uploads.strikinglycdn.com/files/b63e7279-fb73-45e4-8831-d902a9cebd3c/26909367778.pdf
- https://uploads.strikinglycdn.com/files/05670fb6-0cab-4f78-81e5-49671d8ece62/sagoxigelukasateranu.pdf
- https://site-1039319.mozfiles.com/files/1039319/1282938339.pdf
- https://site-1043176.mozfiles.com/files/1043176/45962950405.pdf
- https://site-1036775.mozfiles.com/files/1036775/nijufoveg.pdf
- https://site-1038810.mozfiles.com/files/1038810/5590359198.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1039319.mozfiles.com
- site-1043176.mozfiles.com
- site-1036775.mozfiles.com
- site-1038810.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report