SUSPICIOUS — vuzijelizude.pdf
SUSPICIOUS — vuzijelizude.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
bdaf276c54e421ad2c5c6c4749bbb184f7f06086e8147ef901afb3912a4f70d1 - SHA-1:
768e5a2c96e2f2c645da90bc9f37a41b0db6f27e - MD5:
bc71b70031575c93ef6e1992bbdccbbc - ssdeep:
1536:SGFdv1HzKPPp+dXtIeN1r9hoLUFV8KV+qK0MiP/86:LFd9TKPh+dXWeNWYFGm1MiPp - TLSH:
T13934BFF310ABDDCD2A876F07AEB61049644AC788613697B014C9B77CC8BC9FCAD04965 - Submitted as: vuzijelizude.pdf
- File type: pdf · Size: 54135 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=dezan%20shira%20and%20associates%20china, https://uploads.strikinglycdn.com/files/cdfb95b8-fc3f-4b19-ae58-f376a579b52e/88628093889.pdf, https://tiposowa.weebly.com/uploads/1/3/1/1/131164246/tamabetev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=dezan%20shira%20and%20associates%20china
- https://uploads.strikinglycdn.com/files/cdfb95b8-fc3f-4b19-ae58-f376a579b52e/88628093889.pdf
- https://tiposowa.weebly.com/uploads/1/3/1/1/131164246/tamabetev.pdf
- https://uploads.strikinglycdn.com/files/70ac7533-54e2-4889-8969-530d28fe62f2/vesewetaleku.pdf
- https://uploads.strikinglycdn.com/files/04950f14-1928-4846-9b80-847978420207/78924701255.pdf
- https://s3.amazonaws.com/henghuili-files2/97670321406.pdf
- https://uploads.strikinglycdn.com/files/7f193e18-9f35-48f7-98c0-39b0184d879c/xiwobevolulewutuv.pdf
- https://uploads.strikinglycdn.com/files/06a114fc-ee58-41c5-9cae-4a2a05b1921c/36085387555.pdf
- https://cdn-cms.f-static.net/uploads/4417675/normal_5fa1e1916c4b5.pdf
- https://uploads.strikinglycdn.com/files/20e58f2c-ac55-4205-855a-55a670056e68/dewufotivuveru.pdf
- https://futokiwusilo.weebly.com/uploads/1/3/4/4/134458686/396947d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- tiposowa.weebly.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- futokiwusilo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report