SUSPICIOUS — zozatamunozawefivoj.pdf
SUSPICIOUS — zozatamunozawefivoj.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4ebf0b212552eae00b0aefccca3866a0642dc88817ff227169521bb64cfbff47 - SHA-1:
bca6714dab1a1575d09972fdcacc99e230688110 - MD5:
736ae5ac44bdf49d7d68c4d6d0b56f9e - ssdeep:
768:UWgGzpDutf0JJAMoRbxbNan7G0mC8bDOJevTs4dd:qGFi1/b0n7IC/gs4dd - TLSH:
T144308CF30067ED4D368AEF036DAA1299A145C7896132A7A158CC76BCC8BC6BD6E00951 - Submitted as: zozatamunozawefivoj.pdf
- File type: pdf · Size: 37367 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=cambridge+checkpoint+english+workbook+9+answers+pdf, https://site-1041384.mozfiles.com/files/1041384/mawevesume.pdf, https://site-1041169.mozfiles.com/files/1041169/gevadibevitukajumifegofu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=cambridge+checkpoint+english+workbook+9+answers+pdf
- https://site-1041384.mozfiles.com/files/1041384/mawevesume.pdf
- https://site-1041169.mozfiles.com/files/1041169/gevadibevitukajumifegofu.pdf
- https://site-1038788.mozfiles.com/files/1038788/wumulanupuf.pdf
- https://site-1037142.mozfiles.com/files/1037142/wubupivuraduve.pdf
- https://cdn.shopify.com/s/files/1/0432/6454/0827/files/90614822987.pdf
- https://cdn.shopify.com/s/files/1/0433/3748/2405/files/62493458186.pdf
- https://cdn.shopify.com/s/files/1/0485/9009/4501/files/google_phone_book_contacts.pdf
- http://jusiriw.benjaminkrudwig.com/uploads/1/3/0/7/130776866/a1d704606e8576.pdf
- http://files.ironbreedlemc.org/uploads/1/3/1/3/131398140/168542.pdf
- http://bupov.mymariavictoriawtx.com/uploads/1/3/0/7/130739456/mewibolegexerukuwore.pdf
- http://files.cateringandcreations.net/uploads/1/3/0/8/130814513/9295549.pdf
- https://site-1039500.mozfiles.com/files/1039500/baferumubidalugofizerom.pdf
- https://site-1039400.mozfiles.com/files/1039400/detovolibisuvip.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1041384.mozfiles.com
- site-1041169.mozfiles.com
- site-1038788.mozfiles.com
- site-1037142.mozfiles.com
- cdn.shopify.com
- jusiriw.benjaminkrudwig.com
- files.ironbreedlemc.org
- bupov.mymariavictoriawtx.com
- files.cateringandcreations.net
- site-1039500.mozfiles.com
- site-1039400.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report