SUSPICIOUS — vozevogos.pdf
SUSPICIOUS — vozevogos.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
aa500b4fd2b898b969d0cb5220d91fa68af5206c4d218be2ef6c2498e79a7fe1 - SHA-1:
c0cbd0072a18fc7ca1039cc71151a8cad9fb7bba - MD5:
fcb92815583a0cf2955cf42ccf7ffe0c - ssdeep:
768:EgGzpDpptj6nEJ2OK4HG4OrvXiYdrGjy1c5rpswqIh+mtN7+fm6RXBfvZsmWo:xGF1pJqGu14rmKB+flRXBfhsmWo - TLSH:
T11F328DF350A3DD8D7E87AF83ADB71199608EC388A1269751448C3B6CD4BC5ADBF10960 - Submitted as: vozevogos.pdf
- File type: pdf · Size: 45129 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=payday%202%20t%C3%BCrk%C3%A7e%20yama%20indir%20tamindir, https://cdn-cms.f-static.net/uploads/4366976/normal_5f8858f5c295f.pdf, https://cdn-cms.f-static.net/uploads/4365553/normal_5f88b87624e0f.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=payday%202%20t%C3%BCrk%C3%A7e%20yama%20indir%20tamindir
- https://cdn-cms.f-static.net/uploads/4366976/normal_5f8858f5c295f.pdf
- https://cdn-cms.f-static.net/uploads/4365553/normal_5f88b87624e0f.pdf
- https://cdn-cms.f-static.net/uploads/4368972/normal_5f88b7437bf43.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f87c03571320.pdf
- https://cdn.shopify.com/s/files/1/0496/3001/9780/files/horse_poems_short.pdf
- https://cdn.shopify.com/s/files/1/0430/7111/1330/files/warmness_on_the_soul_piano.pdf
- https://cdn.shopify.com/s/files/1/0435/7432/9507/files/firebaugh_high_school_principal.pdf
- https://cdn.shopify.com/s/files/1/0440/7584/3736/files/predicas_cristianas_en_power_point.pdf
- https://uploads.strikinglycdn.com/files/1b5db084-c3da-4da2-97ac-17edb2380e43/lubudoxinijobejefuta.pdf
- https://uploads.strikinglycdn.com/files/5dc447f3-248b-49f7-8164-b88466f80f3c/34849341744.pdf
- https://uploads.strikinglycdn.com/files/9574cf8f-a001-42fe-be98-803b2a1da354/62197201566.pdf
- https://uploads.strikinglycdn.com/files/f05c76d7-eedc-43cf-8fcb-33598aa6e486/liruxugofuvedibasenim.pdf
- https://site-1039873.mozfiles.com/files/1039873/69699423058.pdf
- https://site-1042349.mozfiles.com/files/1042349/matuxoxa.pdf
- https://site-1040426.mozfiles.com/files/1040426/tepodot.pdf
- https://site-1037098.mozfiles.com/files/1037098/92927113309.pdf
- https://uploads.strikinglycdn.com/files/729eba80-a335-4482-8601-9cf57f6d307b/vurujuwizugima.pdf
- https://uploads.strikinglycdn.com/files/6909eb88-b1b9-4b83-aaee-5aaac5647aa8/movatuzub.pdf
- https://uploads.strikinglycdn.com/files/61e8c188-8b1a-4298-9978-8aa2708632b3/fidoxovodib.pdf
- https://uploads.strikinglycdn.com/files/f7838eea-bdbe-4f12-948f-d862d7e8428e/bakokamera.pdf
- https://uploads.strikinglycdn.com/files/3b33c581-bbda-40e9-a682-70d71550f65f/85110155422.pdf
- https://cdn.shopify.com/s/files/1/0478/8315/7670/files/23088815276.pdf
- https://cdn.shopify.com/s/files/1/0433/8014/6343/files/xekepunabopepugize.pdf
- https://cdn.shopify.com/s/files/1/0435/7970/3451/files/zosiduregawapuda.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1039873.mozfiles.com
- site-1042349.mozfiles.com
- site-1040426.mozfiles.com
- site-1037098.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report