SUSPICIOUS — wepirorogekozuvo.pdf
SUSPICIOUS — wepirorogekozuvo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e0d85230652581bb2b493e430e3d80d2656965511d2a9a572359640b9a3258da - SHA-1:
3b5a856be09844faf0bb79937feaa69248ba8ea1 - MD5:
f544d115d4215cd5a610f725039741de - ssdeep:
1536:DGFZeVOLBmnTd4Sz6bYt31u8+xVXZ95U+5y5tx:SFZeVLn2S+bCeVXZU - TLSH:
T186337DF30097EC8D7ACA9B07EDBB016D604AC7886236D7A04898775CD17C6ED6E10652 - Submitted as: wepirorogekozuvo.pdf
- File type: pdf · Size: 49473 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=trials%20of%20mana%20class%20guide, https://uploads.strikinglycdn.com/files/52b4bdc9-ba39-4094-b38a-56f07fb32ef9/felupivuvuxudubavibug.pdf, https://uploads.strikinglycdn.com/files/3e298061-6a85-4f59-9dff-0fab6c681995/90389885443.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=trials%20of%20mana%20class%20guide
- https://uploads.strikinglycdn.com/files/52b4bdc9-ba39-4094-b38a-56f07fb32ef9/felupivuvuxudubavibug.pdf
- https://uploads.strikinglycdn.com/files/3e298061-6a85-4f59-9dff-0fab6c681995/90389885443.pdf
- https://uploads.strikinglycdn.com/files/8244317a-95cb-4d55-a6e4-87cbeacb36bd/88580886860.pdf
- https://uploads.strikinglycdn.com/files/520bc97e-f183-4449-8a0d-a26513071484/88332713712.pdf
- https://uploads.strikinglycdn.com/files/660baaa1-b157-4394-b9bb-ad8ad1707fab/88849482137.pdf
- https://cdn.shopify.com/s/files/1/0483/2575/5043/files/phantom_doctrine_compounds_guide.pdf
- https://cdn.shopify.com/s/files/1/0428/1414/4675/files/moxefibegiv.pdf
- https://cdn.shopify.com/s/files/1/0433/1136/6309/files/exploracion_de_glandula_tiroides.pdf
- https://cdn.shopify.com/s/files/1/0435/3025/6536/files/sb6121_firmware_upgrade.pdf
- https://cdn.shopify.com/s/files/1/0469/4963/0113/files/intex_pool_hoses_near_me.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f881cc892360.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f88fcfa8b41a.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f87a0b791d7b.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f87194edd39b.pdf
- https://uploads.strikinglycdn.com/files/d75c0b2c-26a5-40d8-876e-097cfda93903/bifob.pdf
- https://uploads.strikinglycdn.com/files/e27656a4-b527-421a-a684-c74b85f9c4d7/34191216278.pdf
- https://uploads.strikinglycdn.com/files/d55af780-1791-4eab-b9cb-876aa1b44846/77582343766.pdf
- https://uploads.strikinglycdn.com/files/a0dda21a-5ef7-437a-ab71-c04f8ec19eb9/34341070570.pdf
- https://cdn.shopify.com/s/files/1/0437/5992/7448/files/jogos_de_fazendas_gratis.pdf
- https://cdn.shopify.com/s/files/1/0437/5930/4858/files/tajurog.pdf
- https://cdn.shopify.com/s/files/1/0495/8686/4278/files/64599700648.pdf
- https://cdn.shopify.com/s/files/1/0433/9594/0503/files/15073633184.pdf
- https://cdn.shopify.com/s/files/1/0487/9748/3173/files/64261680235.pdf
- https://cdn.shopify.com/s/files/1/0433/4924/6102/files/crime_patrol_26th_november_2015.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report