SUSPICIOUS — zeveboganuza_zewegon.pdf
SUSPICIOUS — zeveboganuza_zewegon.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4348f139e22df104dd3909ab539ae799bdc81ed515ebd29c2813a508bbcb2147 - SHA-1:
b4189c8264ffe9ec64fac2c8a0b5ce3933c7281e - MD5:
2b53072ed4bc3a171e0121a69b4bd81a - ssdeep:
1536:vGFWeRuzDU06Bg/cdO3ENc6JDqIATMbLh6WqxWTLal:eFWewzDUDACO3ODDqIATMbtOWTI - TLSH:
T168348EF300D7EE8C7F8AAB036CEB116E118EC7483127D7909489676EC57C6AD6E50960 - Submitted as: zeveboganuza_zewegon.pdf
- File type: pdf · Size: 57431 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=telecharger%20caneco%20bt%205.4%20avec%20crack, https://site-1040575.mozfiles.com/files/1040575/wurovu.pdf, https://site-1043314.mozfiles.com/files/1043314/absurdistan_gary_shteyngart.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=telecharger%20caneco%20bt%205.4%20avec%20crack
- https://site-1040575.mozfiles.com/files/1040575/wurovu.pdf
- https://site-1043314.mozfiles.com/files/1043314/absurdistan_gary_shteyngart.pdf
- https://site-1038892.mozfiles.com/files/1038892/kiwofodeb.pdf
- https://site-1038789.mozfiles.com/files/1038789/disejonegu.pdf
- https://site-1037103.mozfiles.com/files/1037103/rotizerinejowezaluzedowi.pdf
- https://uploads.strikinglycdn.com/files/fd33fcfe-5243-4553-9def-9c3ea7259a51/16948112059.pdf
- https://uploads.strikinglycdn.com/files/589c935b-8d28-4b8f-93df-15365a84270e/biwifeta.pdf
- https://uploads.strikinglycdn.com/files/68182195-4de8-4c07-b813-c6b379b94a8c/37402235543.pdf
- https://uploads.strikinglycdn.com/files/5e04f8c0-fd0b-4dcc-965c-39318a53bdee/97757059646.pdf
- https://cdn-cms.f-static.net/uploads/4368777/normal_5f8819c44537d.pdf
- https://cdn-cms.f-static.net/uploads/4366676/normal_5f88076f7003a.pdf
- https://cdn.shopify.com/s/files/1/0497/4863/9907/files/past_tense_of_drive_a_hard_bargain.pdf
- https://cdn.shopify.com/s/files/1/0499/7234/7048/files/34195620626.pdf
- https://cdn.shopify.com/s/files/1/0493/4280/8218/files/nataj.pdf
- https://cdn.shopify.com/s/files/1/0434/7471/4784/files/romokefa.pdf
- https://uploads.strikinglycdn.com/files/41f8c9b1-77a7-42e9-8fde-63f98dd1be31/80516068244.pdf
- https://uploads.strikinglycdn.com/files/6b402648-ad0e-4ba0-b3a5-069c0fe34505/ravanepuwer.pdf
- https://uploads.strikinglycdn.com/files/f1c77af4-1465-4b68-90fe-cc102cc03be7/zibodose.pdf
- https://uploads.strikinglycdn.com/files/41a1da00-c785-44e5-8f6f-e129987fb901/tewemafobijanelimojunaxab.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/13b897d65df.pdf
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/bekipujedolejed.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/zutilipevozafeguwu.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- site-1040575.mozfiles.com
- site-1043314.mozfiles.com
- site-1038892.mozfiles.com
- site-1038789.mozfiles.com
- site-1037103.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- jufaxexave.weebly.com
- xazapadikud.weebly.com
- guwomenod.weebly.com
- genigudepa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report