SUSPICIOUS — vekimo.pdf
SUSPICIOUS — vekimo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c0254f20a066f54c6bbdecc573b6497b3e73f353644cc1a0a9efafe045b38feb - SHA-1:
3dd5340786f4deeee7681d8865c8e6d8ab89a0d5 - MD5:
035850e45999e000a55af2ca92211ddc - ssdeep:
768:bgGzpDhpfQewwmDWTI9GdmkZVA49SM1CuSvsPRjxodWI0VDTANvcplTNrnp4/yV5:kGFVpYyZT9HvVDcNvClpzeyVQcqI - TLSH:
T128329EF340A7FD4C768A9F47ADD7019A658EC78C61339B614088632CD5BCAFD6E10911 - Submitted as: vekimo.pdf
- File type: pdf · Size: 44881 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=where%20does%20streamlabs%20obs%20save%20recor, https://cdn.shopify.com/s/files/1/0437/4082/3706/files/kenny_rogers_you_cant_make_old_friends_listen.pdf, https://cdn.shopify.com/s/files/1/0500/2513/6278/files/zedunamutule.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=where%20does%20streamlabs%20obs%20save%20recor
- https://cdn.shopify.com/s/files/1/0437/4082/3706/files/kenny_rogers_you_cant_make_old_friends_listen.pdf
- https://cdn.shopify.com/s/files/1/0500/2513/6278/files/zedunamutule.pdf
- https://cdn.shopify.com/s/files/1/0428/8331/7926/files/types_of_business_communication.pdf
- https://cdn.shopify.com/s/files/1/0496/2333/5063/files/godosidojuxifixipeka.pdf
- https://cdn.shopify.com/s/files/1/0484/0158/0190/files/nimbex_davis_drug_guide.pdf
- https://site-1043174.mozfiles.com/files/1043174/33637271310.pdf
- https://site-1039494.mozfiles.com/files/1039494/zozoxexebe.pdf
- https://site-1038423.mozfiles.com/files/1038423/60760640687.pdf
- https://site-1040396.mozfiles.com/files/1040396/newododufe.pdf
- https://site-1039749.mozfiles.com/files/1039749/93866821447.pdf
- https://cdn-cms.f-static.net/uploads/4366042/normal_5f87eb972eb4f.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f8750bd00a07.pdf
- https://cdn-cms.f-static.net/uploads/4370777/normal_5f881d54d0f8b.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/zanazanekoxel.pdf
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/sezifavakotunat-xorexojatelo-torixuxix-sarokuxadikajub.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/mosikeriz-bidepeb-tizon-nenefaxupi.pdf
- https://bibeliki.weebly.com/uploads/1/3/0/7/130738572/pekaberosevaji-navoxojulan.pdf
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f8764ad95d24.pdf
- https://cdn-cms.f-static.net/uploads/4367648/normal_5f87a53a9e1fa.pdf
- https://cdn.shopify.com/s/files/1/0479/6402/9095/files/65697975758.pdf
- https://cdn.shopify.com/s/files/1/0486/2456/6432/files/pufejirusoze.pdf
- https://cdn.shopify.com/s/files/1/0467/7763/0873/files/lamotarurifujekomuf.pdf
- https://cdn.shopify.com/s/files/1/0429/1097/4111/files/the_outsiders_chapter_2_answers.pdf
- https://cdn.shopify.com/s/files/1/0500/6298/3331/files/sivexeziz.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1043174.mozfiles.com
- site-1039494.mozfiles.com
- site-1038423.mozfiles.com
- site-1040396.mozfiles.com
- site-1039749.mozfiles.com
- cdn-cms.f-static.net
- bedizegoresupa.weebly.com
- xazapadikud.weebly.com
- xojisige.weebly.com
- bibeliki.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report