SUSPICIOUS — vegifugewoteda.pdf
SUSPICIOUS — vegifugewoteda.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c331cd7ff51249f5c9aaa0e525552129aaf712f18a7b32db1f5da2ef9ae2f80f - SHA-1:
9f498e6df74b158c7e753a7dd5f6add7af2ba6ba - MD5:
7818b3caf83adffb510b2f908d8b342d - ssdeep:
768:dgGzpDeEimzBlJ+DqgL/1QNxEY9Qf3NVfJNxDffRnaRE8:eGFqEBvN+3vzxtaRE8 - TLSH:
T19831AFF350A7ED4D7686AB03AAE82558640AC78A6172A3E454987B7CC47C7BC3E40C71 - Submitted as: vegifugewoteda.pdf
- File type: pdf · Size: 43225 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=map+bangkok+pdf, https://cdn.shopify.com/s/files/1/0427/6633/6167/files/widagerusataw.pdf, https://cdn.shopify.com/s/files/1/0429/0999/1075/files/naruribifuxobiretarin.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=map+bangkok+pdf
- https://cdn.shopify.com/s/files/1/0427/6633/6167/files/widagerusataw.pdf
- https://cdn.shopify.com/s/files/1/0429/0999/1075/files/naruribifuxobiretarin.pdf
- https://cdn.shopify.com/s/files/1/0449/2269/9943/files/6._2_biomes_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0428/8466/1414/files/windows_98_second_edition.pdf
- https://cdn.shopify.com/s/files/1/0463/1943/5936/files/ie-_3000-_4tc_ordering_guide.pdf
- http://files.northwoods-wealth-management.com/uploads/1/3/2/8/132814996/86a8c20ab326dbc.pdf
- http://files.dheifetz.com/uploads/1/3/0/8/130874148/vokugas.pdf
- http://jutef.euroforestireland.ie/uploads/1/3/0/7/130775363/6f4d61ab37f9.pdf
- https://cdn.shopify.com/s/files/1/0462/0134/0057/files/inspiron_14_5000.pdf
- https://cdn.shopify.com/s/files/1/0439/0364/7912/files/anything_to_mp3.pdf
- https://site-1037837.mozfiles.com/files/1037837/bevawogimifopixi.pdf
- https://site-1036840.mozfiles.com/files/1036840/18893402739.pdf
- https://site-1036884.mozfiles.com/files/1036884/tadudijudabapixirawid.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- files.northwoods-wealth-management.com
- files.dheifetz.com
- site-1037837.mozfiles.com
- site-1036840.mozfiles.com
- site-1036884.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
- jutef.euroforestireland.ie
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report