SUSPICIOUS — bugevig.pdf
SUSPICIOUS — bugevig.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
aff272dd258b17cd4421e72b43a0bb4b755b6bfcad021466a6aca6542609405e - SHA-1:
04eaba13f6ec5c6f797cf2e1fb34436580eca6fd - MD5:
71abb1458263501a7fa53c3f6c874e9b - ssdeep:
768:mgGzpDCjgVNyfZbHGG810D/qySLp+ZcFb+xrg/bVEZtCA/J4JC8aVySFM:zGFWsvyxbw+48cFb+x0xEHCAuLaVySFM - TLSH:
T1CE339DF380B7ED4CBACFAB0799A6019D614AC64D21329660548C7B2CC47C7FE6E11B51 - Submitted as: bugevig.pdf
- File type: pdf · Size: 47885 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=aruba+iap-+205, https://uploads.strikinglycdn.com/files/37cbf557-ed10-4a3f-89fb-b41f1091ec12/tuvumipureva.pdf, https://uploads.strikinglycdn.com/files/ffa015ee-9027-40bf-b13a-6916ef30d163/46151098650.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=aruba+iap-+205
- https://uploads.strikinglycdn.com/files/37cbf557-ed10-4a3f-89fb-b41f1091ec12/tuvumipureva.pdf
- https://uploads.strikinglycdn.com/files/ffa015ee-9027-40bf-b13a-6916ef30d163/46151098650.pdf
- https://uploads.strikinglycdn.com/files/82e9766a-5ee7-4067-9bc5-0d979430fccf/21632839460.pdf
- https://uploads.strikinglycdn.com/files/b8c56310-160e-4c11-b852-b8033a5d5bf7/kuverodurajiba.pdf
- https://uploads.strikinglycdn.com/files/5aa44775-56c3-4575-9dbe-8a57e6f7c41a/34521205642.pdf
- http://ragizepir.tayloredteachings.com/uploads/1/3/0/8/130874376/b0ea24519ac.pdf
- http://sedisede.maconmedicalgroup.com/uploads/1/3/1/4/131483266/newubot_jawoxatet_vulotalavate_zanota.pdf
- http://files.rockingb5.ca/uploads/1/3/0/8/130814430/desujiretanujuwusa.pdf
- http://files.evangeliodeamor.org/uploads/1/3/1/3/131380687/9599045.pdf
- https://site-1036830.mozfiles.com/files/1036830/77839635373.pdf
- https://site-1037121.mozfiles.com/files/1037121/gelotujolatigadewesare.pdf
- https://site-1038880.mozfiles.com/files/1038880/ponizudobaganivux.pdf
- https://site-1038407.mozfiles.com/files/1038407/berezewob.pdf
- https://site-1040134.mozfiles.com/files/1040134/fenuj.pdf
- https://cdn.shopify.com/s/files/1/0434/2277/7496/files/wonajonalimiwexemad.pdf
- https://cdn.shopify.com/s/files/1/0437/4514/9079/files/samsung_galaxy_tab_a_8.0_sm-t350_review.pdf
- https://cdn.shopify.com/s/files/1/0438/9565/2504/files/kingroot_android_6.0.1_marshmallow_apk.pdf
- https://cdn.shopify.com/s/files/1/0434/8503/6706/files/pharmaceutical_distribution_business_plan.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- ragizepir.tayloredteachings.com
- sedisede.maconmedicalgroup.com
- files.rockingb5.ca
- files.evangeliodeamor.org
- site-1036830.mozfiles.com
- site-1037121.mozfiles.com
- site-1038880.mozfiles.com
- site-1038407.mozfiles.com
- site-1040134.mozfiles.com
- cdn.shopify.com
- 2b.gq
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report