SUSPICIOUS — varakonazefepax.pdf
SUSPICIOUS — varakonazefepax.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
934241ba71e242cc992c79eb6933d3368e6b53ff94364fcc04b4736e87809981 - SHA-1:
ce7d784ccd079753fe99f8a2556ac77917e6c12c - MD5:
3748a78ecd241004b8b3b951455af4a1 - ssdeep:
1536:kGFUStD7QlAsspU3EuAgFM1U5MMSv9HtnfBi33pWK/bnY045x7:xFUiDM/jAwGU7wmHv7G - TLSH:
T1EB38D0F30157DC4C76C6FF17A9EA1098220B96986066B76491C8B77CC9BC2FC3E11A50 - Submitted as: varakonazefepax.pdf
- File type: pdf · Size: 80763 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=rth2300+wiring+diagram, https://uploads.strikinglycdn.com/files/4c866799-64e0-4715-8aad-dd22371bde3f/lidajusosiligarejeno.pdf, https://uploads.strikinglycdn.com/files/92fa68fe-6774-4ffc-b2f9-5e2c46da14d9/sinupenamedanimif.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=rth2300+wiring+diagram
- https://uploads.strikinglycdn.com/files/4c866799-64e0-4715-8aad-dd22371bde3f/lidajusosiligarejeno.pdf
- https://uploads.strikinglycdn.com/files/92fa68fe-6774-4ffc-b2f9-5e2c46da14d9/sinupenamedanimif.pdf
- https://uploads.strikinglycdn.com/files/5cd28e2f-48ba-4ae8-8dcd-8a298e0a033e/56240547244.pdf
- https://uploads.strikinglycdn.com/files/ebc60593-6ea0-474b-a330-c6362e6ce562/17614298485.pdf
- https://uploads.strikinglycdn.com/files/0bb1f5b1-b48c-4d8d-8ddf-e2c061f3e628/24364140874.pdf
- https://uploads.strikinglycdn.com/files/c0c0ffb4-2aa4-4118-b38e-43b509150e3f/13538533500.pdf
- https://uploads.strikinglycdn.com/files/afcb3cc1-55fb-4448-9e15-1bedafbf5931/rugubaxu.pdf
- https://uploads.strikinglycdn.com/files/49fda0af-6e9f-4b8b-9740-6ff78028c529/voxavilujir.pdf
- http://taxegepa.keepitstraightsis.com/uploads/1/3/0/9/130969336/0ada019d9f0e.pdf
- http://famib.dpaulart.com/uploads/1/3/0/7/130775299/9862381.pdf
- http://files.alcovitusa.com/uploads/1/3/0/8/130814611/3833568.pdf
- http://files.campbellmosspto.com/uploads/1/3/1/4/131454731/3e0eef9.pdf
- https://uploads.strikinglycdn.com/files/a8b24306-e84e-4287-9906-551b0c1dc0db/89155941642.pdf
- https://uploads.strikinglycdn.com/files/00d7609a-0e1d-4c35-98ef-af7dd9a41604/nepuvopuzopogumukarovakin.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- taxegepa.keepitstraightsis.com
- famib.dpaulart.com
- files.alcovitusa.com
- files.campbellmosspto.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report