SUSPICIOUS — vasamaf.pdf
SUSPICIOUS — vasamaf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
f71a459fc2790325cc84c77c210c15f4ebe6c92aea8750c46c2a42b5529dd4fe - SHA-1:
4922005983f1d6c669690108073f68fbb7cf70a5 - MD5:
72e1fc2589fd995bac9ac39f982afb3a - ssdeep:
1536:JhyR73jUvlAnpeYsWDuxofUSueel+m9oY99AsS+W8pOGo7vIWyvHeeFWR:ryx3uluMYaxidue5m9Z999S9Gwvk+f - TLSH:
T11F39D0F3508BDE1C77979F0768AF26949049E7DC6222AF804184B75CD4ACEBE7E04A01 - Submitted as: vasamaf.pdf
- File type: pdf · Size: 86838 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://catamma.ru/uplcv?utm_term=parapet+details+pdf, https://nstyapi.com/resimler/files/58258860007.pdf, http://baanpowertrain.com/wp-content/plugins/formcraft/file-upload/server/content/files/16077aaa3c8197---pasakujozes.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://catamma.ru/uplcv?utm_term=parapet+details+pdf
- https://nstyapi.com/resimler/files/58258860007.pdf
- http://baanpowertrain.com/wp-content/plugins/formcraft/file-upload/server/content/files/16077aaa3c8197---pasakujozes.pdf
- http://globaltruthmediagroup.com/clients/a/aa/aa8380eac451876ae6ab993bf3a720d6/File/5346587265.pdf
- https://sellerflows.com/wp-content/plugins/super-forms/uploads/php/files/5d9fc89e2b1fb4cc804a969aca206391/laliwizuvex.pdf
- https://lakeshoresmilesdentistry.com/wp-content/plugins/super-forms/uploads/php/files/911ckdcpkjbkqgnh2i4e8s18c7/rojajaselipurekuxog.pdf
- http://romengo.com/ckfinder/userfiles/files/gurose.pdf
- http://upperdublin1970.com/clients/3/3b/3b2fb281f4756d03d37a29c41a8c1d95/File/ziwinejobojerikezemox.pdf
- https://pnvvr.ro/userfiles/file/kijele.pdf
- https://luyenthitoeic.info/userfiles/file/povifezumosuguk.pdf
- https://dungcuruamui.com/wp-content/plugins/super-forms/uploads/php/files/7kmj1i2gnljk342mlqfiaqh5vv/semefagek.pdf
- http://maslatalaia.com/userfiles/file/megalujexejato.pdf
- http://niestachow.pl/data/aktualnosci_imgs/file/46339778136.pdf
- http://fvhs1970.com/clients/876770/File/81021947531.pdf
- http://abwlondonblvd.com/uploads/files/81109274211.pdf
- https://divorcioconsensual.com.br/wp-content/plugins/super-forms/uploads/php/files/04a706d0771e8defd8465f88ec530daf/mirumadikijuropiludes.pdf
- http://www.mondzorgvesa-voorschoten.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607dcc57671bc---fivigexadetexaniwi.pdf
- https://maxflowfans.com/userfiles/file/19700527701.pdf
- https://izharfoster.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f0d5de6714---64035677990.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b50262c7665---safugibemerezika.pdf
- http://botosani.ro/img/uploads/file/36270756064.pdf
- http://3qlohas.com/CKEdit/upload/files/97030507377.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- catamma.ru
- nstyapi.com
- baanpowertrain.com
- globaltruthmediagroup.com
- sellerflows.com
- lakeshoresmilesdentistry.com
- romengo.com
- upperdublin1970.com
- luyenthitoeic.info
- dungcuruamui.com
- maslatalaia.com
- niestachow.pl
- fvhs1970.com
- abwlondonblvd.com
- divorcioconsensual.com.br
- www.mondzorgvesa-voorschoten.nl
- maxflowfans.com
- izharfoster.com
- www.1000ena.com
- 3qlohas.com
- www.w3.org
- purl.org
- ns.adobe.com
- pnvvr.ro
- botosani.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report