SUSPICIOUS — semavozugaxiluluzevew.pdf
SUSPICIOUS — semavozugaxiluluzevew.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
c619710342b6a2f3bd07288efafc361ecf0487ee204663c75e19ac6cda58799a - SHA-1:
04f51d5e4c26a672d63c993ffec675f415976309 - MD5:
59b9e675ec847cb0dbdf6cee3dd6e23f - ssdeep:
768:9gGzpDZPYCesDlcg9blT/kxLUwMxA8r8hZdI0MVtVsc3Lr+sCVWBeFDX:+GFNZesZHkgpAdxh9c3n+sgSeFDX - TLSH:
T1CF34AEF39167EDCC7F8A9B036DB510586146DA886132DAE054993BBC887C6FD7E04A20 - Submitted as: semavozugaxiluluzevew.pdf
- File type: pdf · Size: 52955 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=price+comparison+excel, https://cdn.shopify.com/s/files/1/0454/3050/5628/files/pokemon_colosseum_xd_iso.pdf, https://cdn.shopify.com/s/files/1/0483/4869/2631/files/94612574704.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=price+comparison+excel
- https://cdn.shopify.com/s/files/1/0454/3050/5628/files/pokemon_colosseum_xd_iso.pdf
- https://cdn.shopify.com/s/files/1/0483/4869/2631/files/94612574704.pdf
- https://cdn.shopify.com/s/files/1/0483/9043/9080/files/serexin_pills_reviews.pdf
- https://site-1040132.mozfiles.com/files/1040132/32714787527.pdf
- https://site-1039923.mozfiles.com/files/1039923/4271254589.pdf
- https://site-1036686.mozfiles.com/files/1036686/gipilup.pdf
- https://site-1039316.mozfiles.com/files/1039316/tepevotarow.pdf
- https://site-1037029.mozfiles.com/files/1037029/zebuv.pdf
- https://site-1039135.mozfiles.com/files/1039135/fekorewewosipanikavu.pdf
- https://site-1040339.mozfiles.com/files/1040339/buzolonit.pdf
- https://site-1039644.mozfiles.com/files/1039644/28999100841.pdf
- https://site-1037253.mozfiles.com/files/1037253/fenolirejojawenaronalal.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1040132.mozfiles.com
- site-1039923.mozfiles.com
- site-1036686.mozfiles.com
- site-1039316.mozfiles.com
- site-1037029.mozfiles.com
- site-1039135.mozfiles.com
- site-1040339.mozfiles.com
- site-1039644.mozfiles.com
- site-1037253.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report