SUSPICIOUS — zazulolagemadegote.pdf
SUSPICIOUS — zazulolagemadegote.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
3084224f635ab6ed08be2a5cebeac0a248de22ce7b3073449bf175ec201fecd0 - SHA-1:
c9deeb7165de9567663a833b5ad431043bd151c3 - MD5:
1addf3c221979d75ae495101a2055d94 - ssdeep:
1536:GGFHpPH4nrbvLhpUVPlwtNNv+Zk/FrI/JLb:fFHpQnrLL3UVuNNv+ZkN0B - TLSH:
T13033D0F3559BED4DBA86FF1369FE14256489C6887137E2A049CC776CC87C2AE6E00420 - Submitted as: zazulolagemadegote.pdf
- File type: pdf · Size: 52238 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=samsung+galaxy+s9+colors, http://novase.red2green.org/uploads/1/3/1/3/131379655/1397a4191566422.pdf, http://pikor.akchristiantraining.com/uploads/1/3/0/7/130739873/01481.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=samsung+galaxy+s9+colors
- http://novase.red2green.org/uploads/1/3/1/3/131379655/1397a4191566422.pdf
- http://pikor.akchristiantraining.com/uploads/1/3/0/7/130739873/01481.pdf
- http://files.protrip.cz/uploads/1/3/1/4/131438071/f792f.pdf
- http://gubixoxe.near-perfection.com/uploads/1/3/2/8/132814930/8959940.pdf
- http://zakefiru.hookedbylynn.com/uploads/1/3/0/7/130776824/7037105.pdf
- http://namalaj.hunterspointetulsa.com/uploads/1/3/0/8/130874601/geboropejesoguvu.pdf
- https://uploads.strikinglycdn.com/files/af9f2517-9143-416a-b249-52e935a5a60e/pemifuwupuwabukitepo.pdf
- https://uploads.strikinglycdn.com/files/aeca0bb4-c9e4-47fd-82f6-52b8bd670685/lalajobomola.pdf
- https://cdn.shopify.com/s/files/1/0435/2406/3392/files/18871161642.pdf
- https://cdn.shopify.com/s/files/1/0433/5140/8799/files/no_fear_midsummer_nights_dream_act_4_scene_1.pdf
- https://cdn.shopify.com/s/files/1/0488/0492/1509/files/drawing_comics_the_marvel_way.pdf
- https://cdn.shopify.com/s/files/1/0433/9128/7452/files/kevuxupamabeg.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- novase.red2green.org
- pikor.akchristiantraining.com
- gubixoxe.near-perfection.com
- zakefiru.hookedbylynn.com
- namalaj.hunterspointetulsa.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
- files.protrip.cz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report