SUSPICIOUS — vugupafolozir.pdf
SUSPICIOUS — vugupafolozir.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
9b0a79d9412a59d2ae1038ad7f4b891f5bf41d75121ac0441eb17ae7bf7fe419 - SHA-1:
7e836eda374bf07115d06ef65f499be299d73080 - MD5:
a573d5b1d9f3fa4c3e047f54443c3afe - ssdeep:
768:igGzpD6zRkPDOUkvNrLR68/nAO0GZE43g9qb2hL2sET+T5yP3lWP:/GFWzRzUeNR6sAF4QqShH++T83lWP - TLSH:
T1A532AFF361A7ED886B87AF4359B60088714AD78D216297A0A4C8B77DC17C9FD5F00E20 - Submitted as: vugupafolozir.pdf
- File type: pdf · Size: 44657 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=wild+geese+mary+oliver+mla+citation, https://uploads.strikinglycdn.com/files/c742602a-ca9a-412d-bfad-f58834d3aec4/95586801020.pdf, https://uploads.strikinglycdn.com/files/6efdecdc-ac47-4885-a67f-812245f142da/fedubowagipatosovet.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=wild+geese+mary+oliver+mla+citation
- https://uploads.strikinglycdn.com/files/c742602a-ca9a-412d-bfad-f58834d3aec4/95586801020.pdf
- https://uploads.strikinglycdn.com/files/6efdecdc-ac47-4885-a67f-812245f142da/fedubowagipatosovet.pdf
- https://uploads.strikinglycdn.com/files/04741f37-04ad-413d-8fa3-be92bfbfda6d/7899517592.pdf
- https://uploads.strikinglycdn.com/files/a53196e6-d6bf-4a1e-9582-b30e2819a0bf/tukezelinugipew.pdf
- https://uploads.strikinglycdn.com/files/6fd3d126-66c8-4a82-8e0e-93e83cfd2d90/wipodi.pdf
- http://files.nhlbc.org/uploads/1/3/1/4/131438228/pukugozuvikitawiv.pdf
- https://site-1038951.mozfiles.com/files/1038951/nojozeg.pdf
- https://site-1037085.mozfiles.com/files/1037085/27392215485.pdf
- https://uploads.strikinglycdn.com/files/8b3505ca-472d-4f6d-93ff-18b2a11c291e/rekojezapineka.pdf
- https://uploads.strikinglycdn.com/files/999ba5ae-1939-4350-bf9c-e664523fea05/46355013481.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- files.nhlbc.org
- site-1038951.mozfiles.com
- site-1037085.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report