SUSPICIOUS — zezaxokaduxereva.pdf
SUSPICIOUS — zezaxokaduxereva.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2136baaf67f8f7185b32aa359fc154df53d9db14720c4e07624017fd37e1b6a6 - SHA-1:
0a6269a89506b5f1e3875f08426d860900e595c8 - MD5:
1286a68f83d2f0389ebb4f7443a80a8b - ssdeep:
768:9gGzpD0dvIlO6egGZ2MTQpLSc+m69SASplKOjwvR6NOCEy6vFjim8:+GFY2OwWQhj69S5KmoR9C/eFjX8 - TLSH:
T15F33AEF30057EDCC6A8A9F036DAA55AC6189C78C913397A464C87A2DC4BC5BD3E10E52 - Submitted as: zezaxokaduxereva.pdf
- File type: pdf · Size: 52001 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=tim%20duncan%20children%20photos, https://uploads.strikinglycdn.com/files/ca895c4b-e618-4c95-bdef-2091c35cdec0/37804716593.pdf, https://uploads.strikinglycdn.com/files/7dfa7174-7f32-416e-a0f9-f2448d0e8ad6/buxuzub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=tim%20duncan%20children%20photos
- https://uploads.strikinglycdn.com/files/ca895c4b-e618-4c95-bdef-2091c35cdec0/37804716593.pdf
- https://uploads.strikinglycdn.com/files/7dfa7174-7f32-416e-a0f9-f2448d0e8ad6/buxuzub.pdf
- https://uploads.strikinglycdn.com/files/4ba5504d-41eb-4509-83a5-5db3c0612efe/xobemudamovalaxitakatu.pdf
- https://uploads.strikinglycdn.com/files/fc654a5a-452a-4ccb-b6e2-d6b4c466437b/chac_mool_carlos_fuentes_rsum.pdf
- https://nukewixe.weebly.com/uploads/1/3/4/3/134385223/kefilewotosogosu.pdf
- https://uploads.strikinglycdn.com/files/4ba3c5b1-ad52-4d58-8d3a-e250de456af4/toshiba_thrive_at105_android_4.1_update.pdf
- https://uploads.strikinglycdn.com/files/06002de0-a124-4041-a110-4dfdaf38439b/mezukogevulirojivimobiz.pdf
- https://vukibawurop.weebly.com/uploads/1/3/4/6/134601902/peguragave_lejunenagi_gefateni_wanirub.pdf
- https://s3.amazonaws.com/sizadagazagaj/xepobazekafexofi.pdf
- https://s3.amazonaws.com/kiwopusafize/eleonora_edgar_allan_poe_english.pdf
- https://uploads.strikinglycdn.com/files/6c8afdac-9205-4994-b830-ea2aa536fbfc/ruwegi.pdf
- https://uploads.strikinglycdn.com/files/5d673c7a-26cd-47cf-aa3f-6d0fac2f96e9/full_grown_nigerian_dwarf_goats_size.pdf
- https://uploads.strikinglycdn.com/files/cdf5cf32-228c-4419-b914-1d8af56d234d/foravokexojo.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/ee9fec6a8fe.pdf
- https://uploads.strikinglycdn.com/files/886dfccb-0672-4b90-8cd9-16813559e028/obama_disbarred_1993.pdf
- https://uploads.strikinglycdn.com/files/a584d5cb-2ca0-44d9-b97a-eb48ccb8bae8/76256933307.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- nukewixe.weebly.com
- vukibawurop.weebly.com
- s3.amazonaws.com
- sibakixode.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report