SUSPICIOUS — vinoganazoxelikesuv.pdf
SUSPICIOUS — vinoganazoxelikesuv.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
f2f920e907e1deee01529f4cfc0a2a625c48a5401546848e3c2b01c444ab32f6 - SHA-1:
9f572467fd2b2431313dc538e118b2836428b603 - MD5:
d56fde855873cb49125dc1c3e91323c5 - ssdeep:
768:cgGzpDxp7Yh2axZhC4Ot0ZirQ50sKgNh1XQZgshjCdx:5GF1p/injxTNh1XEhjCdx - TLSH:
T171328EF710D7ED8C7A8AAB13ACA7057A114AC78D6132E760098C7B3DD47C6BD6E10921 - Submitted as: vinoganazoxelikesuv.pdf
- File type: pdf · Size: 45424 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=isps%20code%20pdf, https://uploads.strikinglycdn.com/files/b0fed6d0-65c3-4a9f-9cd6-d59e663b5862/gogomaka.pdf, https://uploads.strikinglycdn.com/files/5a26e7e4-42af-4786-9800-24600a86d75d/38199085920.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=isps%20code%20pdf
- https://uploads.strikinglycdn.com/files/b0fed6d0-65c3-4a9f-9cd6-d59e663b5862/gogomaka.pdf
- https://uploads.strikinglycdn.com/files/5a26e7e4-42af-4786-9800-24600a86d75d/38199085920.pdf
- https://uploads.strikinglycdn.com/files/3967f375-771d-49d4-9b6e-8c6f191c2e41/3185700843.pdf
- https://uploads.strikinglycdn.com/files/284aba60-a11e-47f9-9613-5d611ebada92/77342039363.pdf
- https://uploads.strikinglycdn.com/files/1bc6dc9d-2643-4465-b6f6-cdc81433519f/figuboxuximegexekumegeju.pdf
- https://site-1042205.mozfiles.com/files/1042205/77282189153.pdf
- https://site-1040008.mozfiles.com/files/1040008/nejofigatenudifitan.pdf
- https://cdn.shopify.com/s/files/1/0477/1974/3644/files/92499996358.pdf
- https://cdn.shopify.com/s/files/1/0435/2992/8856/files/danish_province_in_the_north_atlantic_ocean_starting_with_f.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/7d3707d5d.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/wogiselaruto-nokage.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/010fdcdf.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/866f9c6956dfb96.pdf
- https://uploads.strikinglycdn.com/files/fb776123-c85e-4093-893d-4ed58a2571cd/90083402225.pdf
- https://uploads.strikinglycdn.com/files/39100645-6439-4ba9-8f1a-3eb1a3aa9b27/mawebevesi.pdf
- https://uploads.strikinglycdn.com/files/458e4460-7c35-46ab-b981-d34fffcdf085/62365824883.pdf
- https://uploads.strikinglycdn.com/files/bb879b8a-c92f-4078-a898-c9d6bdfd11a8/61839459383.pdf
- https://site-1040798.mozfiles.com/files/1040798/12447972438.pdf
- https://site-1040363.mozfiles.com/files/1040363/sisugarokoxewimoxa.pdf
- https://site-1039863.mozfiles.com/files/1039863/dogazibakedo.pdf
- https://site-1038604.mozfiles.com/files/1038604/88583133722.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1042205.mozfiles.com
- site-1040008.mozfiles.com
- cdn.shopify.com
- jakedekokobara.weebly.com
- xojerajap.weebly.com
- dutitujazekap.weebly.com
- loguxofe.weebly.com
- site-1040798.mozfiles.com
- site-1040363.mozfiles.com
- site-1039863.mozfiles.com
- site-1038604.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report