SUSPICIOUS — viresolet.pdf
SUSPICIOUS — viresolet.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
cd6e39c4aad6df1e44f373bc26d90a21519464a049237eb6290c4e57b509796f - SHA-1:
625d46cb7377013ffc2ee9f37ed4ce79bab28c7d - MD5:
a9e496265bb6d76a75a1baf3024180d8 - ssdeep:
768:9gGzpDLjpxlgtLHQcdWk0EnSnun3KFVnfu40G3qXfq5eB4fTN:+GFXjpWjXfb4fTN - TLSH:
T1D3315BF351A7DC8C7A87DF036AEF285D9289D7882272976085D8272CC07C2BD7E00A51 - Submitted as: viresolet.pdf
- File type: pdf · Size: 40604 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=pet%20rescue%20stockton%20ca, https://uploads.strikinglycdn.com/files/7c868263-fbe2-4145-be35-9631ab5453ae/mogigow.pdf, https://uploads.strikinglycdn.com/files/8789dfc9-2606-4630-9ed6-e17be4f17d4b/41293490416.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=pet%20rescue%20stockton%20ca
- https://uploads.strikinglycdn.com/files/7c868263-fbe2-4145-be35-9631ab5453ae/mogigow.pdf
- https://uploads.strikinglycdn.com/files/8789dfc9-2606-4630-9ed6-e17be4f17d4b/41293490416.pdf
- https://uploads.strikinglycdn.com/files/a21072a7-007d-458b-94d7-61d7d6f92b03/lifafojusubadivelopazote.pdf
- https://cdn.shopify.com/s/files/1/0432/9383/5432/files/36807661575.pdf
- https://cdn.shopify.com/s/files/1/0492/3870/4284/files/motil.pdf
- https://cdn.shopify.com/s/files/1/0428/7817/3343/files/901402638.pdf
- https://cdn.shopify.com/s/files/1/0429/6212/4959/files/urpower_humidifier_manual_5l.pdf
- https://cdn.shopify.com/s/files/1/0498/1119/4010/files/vimixira.pdf
- https://cdn.shopify.com/s/files/1/0499/3122/3202/files/solving_inequalities_worksheet_common_core.pdf
- https://cdn.shopify.com/s/files/1/0439/9933/0462/files/gatawozeraros.pdf
- https://cdn.shopify.com/s/files/1/0499/1795/2189/files/sikufubazizat.pdf
- https://cdn.shopify.com/s/files/1/0469/0349/2770/files/decompile_.so_file_from_apk.pdf
- https://s3.amazonaws.com/wonoti/9856360475.pdf
- https://s3.amazonaws.com/mijedusovineti/jurnal_bani_abbasiyah.pdf
- https://s3.amazonaws.com/kavitokolezub/21451903369.pdf
- https://s3.amazonaws.com/leguvefu/25786099591.pdf
- https://s3.amazonaws.com/zetare/mapuwe.pdf
- https://s3.amazonaws.com/sugaguxagu/rudebasopow.pdf
- https://s3.amazonaws.com/leguvefu/gibirugirug.pdf
- https://uploads.strikinglycdn.com/files/91303e2a-83d6-4142-8321-ae1acc04bc27/kipefomagosobawibu.pdf
- https://uploads.strikinglycdn.com/files/397e7312-e151-47fd-bb4f-3f9ec4c21b1e/sikodikato.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report