SUSPICIOUS — zumezokapedurezuzetafi.pdf
SUSPICIOUS — zumezokapedurezuzetafi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2592da06e932edf0e4239f347d9e84f50ea298fbd4dff6710859bfd8bf05788f - SHA-1:
89d83e86216a992ab3b5dc82709e66e6fa5cdbc1 - MD5:
e181f61a979f9862688390eb6a18f7a9 - ssdeep:
1536:aGFFm8JhYXpy3fT7+5oGH73uZeEU9qzAZOWdxJePc:DFFVPHrw374eEUkKPD - TLSH:
T1BE36BFF35497DC9CBA8AEB03A8B314256009D7897277A7245488BB3CC47CABDBE50D50 - Submitted as: zumezokapedurezuzetafi.pdf
- File type: pdf · Size: 66333 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/872b41f3-10a1-4d7e-8e50-032ac166c8e0/11224550140.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=shijou+saikyou+no+deshi+kenichi+ova, https://cdn.shopify.com/s/files/1/0432/8249/7701/files/anatomy_and_physiology_worksheets.pdf, https://cdn.shopify.com/s/files/1/0483/7805/2761/files/napozuriwobufu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=shijou+saikyou+no+deshi+kenichi+ova
- https://cdn.shopify.com/s/files/1/0432/8249/7701/files/anatomy_and_physiology_worksheets.pdf
- https://cdn.shopify.com/s/files/1/0483/7805/2761/files/napozuriwobufu.pdf
- https://cdn.shopify.com/s/files/1/0461/8197/4169/files/uf_student_gardens.pdf
- https://cdn.shopify.com/s/files/1/0431/7206/9525/files/michael_jackson_starsunfolded.pdf
- http://files.oemhondaparts.eu/uploads/1/3/1/4/131406248/2051399.pdf
- http://dojoke.greatervictoriaartistdirectory.com/uploads/1/3/1/4/131453902/wuxipidutuvoxamoz.pdf
- http://files.emilyhuntermft.com/uploads/1/3/0/7/130740051/7d982b1c01ba0d3.pdf
- https://uploads.strikinglycdn.com/files/872b41f3-10a1-4d7e-8e50-032ac166c8e0/11224550140.pdf
- https://uploads.strikinglycdn.com/files/19a14d76-e9fe-4f41-bf87-1c671df12d46/rizelaxigevazoxefu.pdf
- https://uploads.strikinglycdn.com/files/faea676d-7efb-48c2-827f-89d1707ccd8a/zegusoforekuxidanos.pdf
- https://uploads.strikinglycdn.com/files/548ff837-7a8f-43c9-ab67-3b5a097897bc/nemezefomat.pdf
- https://uploads.strikinglycdn.com/files/03fbe4c1-601a-437f-87a5-a9ba58dc3dd6/67757631463.pdf
- https://uploads.strikinglycdn.com/files/0b5261fc-a6fc-48f1-91ba-d397387271c9/muropomozerilano.pdf
- https://uploads.strikinglycdn.com/files/3009aa9c-a30c-481b-b913-ba587cc461f8/49765091976.pdf
- https://uploads.strikinglycdn.com/files/3dbfc01a-7fc1-4b90-8011-f20f3d08568a/53302803270.pdf
- https://uploads.strikinglycdn.com/files/2dc106a5-4c9f-4e66-9a50-db43ea8105a0/bifapuz.pdf
- https://uploads.strikinglycdn.com/files/fb1c11df-4318-40f1-83c2-50dbcc63f324/39112437881.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- files.oemhondaparts.eu
- dojoke.greatervictoriaartistdirectory.com
- files.emilyhuntermft.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report