SUSPICIOUS — wilazetemezef.pdf
SUSPICIOUS — wilazetemezef.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
b4d9dd0dc34809f34f4a668dd8e35b047d817243ca6c4d9f86049baaa7ccce28 - SHA-1:
f0fad31d6e91eec69c5c4441b91b7a85f5247ce3 - MD5:
a4ca911ebd665294e802508f0c42e415 - ssdeep:
768:tgGzpD4iu8Oj8uuKLDMlhExQPIfWq8yWfcnjrTJ4XXb5i:OGFUUOWYDFQfcn2XXb5i - TLSH:
T1CF319DF351B7EC8C7BCE9F0B6DAA15A9608ED78C503B96100588676CC0BC6FD6E01A51 - Submitted as: wilazetemezef.pdf
- File type: pdf · Size: 41948 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=geneva%20convention%20iii%201949%20pdf, https://cdn-cms.f-static.net/uploads/4374853/normal_5f928a52245dd.pdf, https://cdn-cms.f-static.net/uploads/4377663/normal_5f922909504b0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=geneva%20convention%20iii%201949%20pdf
- https://s3.amazonaws.com/kavitokolezub/96243907813.pdf
- https://s3.amazonaws.com/gofiguj/gepevel.pdf
- https://s3.amazonaws.com/fasanag/20115479176.pdf
- https://s3.amazonaws.com/dutimajizowa/free_download_asme_section_ix.pdf
- https://cdn-cms.f-static.net/uploads/4374853/normal_5f928a52245dd.pdf
- https://cdn-cms.f-static.net/uploads/4377663/normal_5f922909504b0.pdf
- https://cdn-cms.f-static.net/uploads/4375210/normal_5f924ddc5f735.pdf
- https://jorimedazaget.weebly.com/uploads/1/3/0/7/130738946/gazosod.pdf
- https://vodexekuteb.weebly.com/uploads/1/3/0/7/130776001/950d1c5f7c64.pdf
- https://mixekolasum.weebly.com/uploads/1/3/4/3/134388380/047a8b3.pdf
- https://jivexine.weebly.com/uploads/1/3/1/3/131380908/de769.pdf
- https://tugajepefur.weebly.com/uploads/1/3/1/4/131453805/wiviza.pdf
- https://s3.amazonaws.com/jamokaroxoj/isa_auditing_standards.pdf
- https://s3.amazonaws.com/henghuili-files2/bhagwat_geeta_in_hindi_format.pdf
- https://s3.amazonaws.com/sepawi/87994591651.pdf
- https://s3.amazonaws.com/leguvefu/1160524433.pdf
- https://cdn-cms.f-static.net/uploads/4368736/normal_5f8786e980153.pdf
- https://cdn-cms.f-static.net/uploads/4379849/normal_5f91cc848cc14.pdf
- https://cdn-cms.f-static.net/uploads/4388617/normal_5f8f3b8f74031.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- jorimedazaget.weebly.com
- vodexekuteb.weebly.com
- mixekolasum.weebly.com
- jivexine.weebly.com
- tugajepefur.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report