SUSPICIOUS — zenilaxadelodidi.pdf
SUSPICIOUS — zenilaxadelodidi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
378d4ba4d54870046b92d557e7124c6904fab41144989037003ba53981dc459b - SHA-1:
1aff64b06df54191ab12477c22a886bd14e395a1 - MD5:
30a4c5badebc783ddfe8eae54a0f7b33 - ssdeep:
768:NgGzpDv/gWwUjFxkeFS8rTGaqDxy8ryKOHPZwSxm1:uGFT/gPSLFpqhrDOvZwSxm1 - TLSH:
T1A2319DF3546BDC4C3B9AAB47ADE21099B109878CA033965458C8B77CC4BC6BC7E11E52 - Submitted as: zenilaxadelodidi.pdf
- File type: pdf · Size: 43111 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafffe.ru/wb?keyword=badtameezdil.net%20movies%20online, https://cdn-cms.f-static.net/uploads/4379856/normal_5fa25ac5a0856.pdf, https://uploads.strikinglycdn.com/files/605d759d-b8cd-4c43-ac8f-fd126c142c9f/34595689882.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/wb?keyword=badtameezdil.net%20movies%20online
- https://cdn-cms.f-static.net/uploads/4379856/normal_5fa25ac5a0856.pdf
- https://uploads.strikinglycdn.com/files/605d759d-b8cd-4c43-ac8f-fd126c142c9f/34595689882.pdf
- https://fezimadi.weebly.com/uploads/1/3/4/4/134487715/kikodikajejiva.pdf
- https://s3.amazonaws.com/besafefaf/tragic_flaw_definition_webster_dictionary.pdf
- https://uploads.strikinglycdn.com/files/cebd7e37-ea42-46c1-87c1-5e8b1c68d1c3/binogozigidipag.pdf
- https://nevosaxovib.files.wordpress.com/2020/11/fizimobaruweboratiweti.pdf
- https://uploads.strikinglycdn.com/files/39d11b26-6837-494e-a1e5-3d7645d2e3f9/seven_bridges_movie_theatre_showtimes.pdf
- https://uploads.strikinglycdn.com/files/c70994fb-5cb2-4101-a6ef-63c10b8832db/ruburugozur.pdf
- https://vedipepemani.files.wordpress.com/2020/11/79326086509.pdf
- https://cdn-cms.f-static.net/uploads/4369165/normal_5f91b04b18777.pdf
- https://uploads.strikinglycdn.com/files/d683b493-0969-4f7b-9254-ba57bd8c4a2a/49427609548.pdf
- https://uploads.strikinglycdn.com/files/d6959fb0-b0fd-4fcc-8062-9d2c69a6c271/realm_grinder_mercenary_tribute.pdf
- https://uploads.strikinglycdn.com/files/1b65ffc6-e5db-4cda-a25a-e138214d810a/38733095539.pdf
- https://s3.amazonaws.com/jaxesabi/vokovowiwezole.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- badtameezdil.net
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- fezimadi.weebly.com
- s3.amazonaws.com
- nevosaxovib.files.wordpress.com
- vedipepemani.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report