SUSPICIOUS — zelex.pdf
SUSPICIOUS — zelex.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
663234001cc4569c3ae1bd79636162f93d149f111613d3cf6934441c4dd8e064 - SHA-1:
ea32f594a89388fe9345dfcd60f0518c6c7f1d10 - MD5:
0662e14c6c7d65ab6981c65420dc42cc - ssdeep:
1536:1GFRefjdeNMBFkuNNk1bSu2pcQ44Wq69w:IFRefqMBF1w1b+HFZ - TLSH:
T1ED358DF320DBDD8CBAC79B03A9FA156D644AD788653297A084887B2CC4BC77C7E11950 - Submitted as: zelex.pdf
- File type: pdf · Size: 57909 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=download%20god%20of%20egypt%20full%20movie%20in, https://uploads.strikinglycdn.com/files/75e56fa3-c855-4248-aeda-d3efe733f293/the_greatest_showman_piano_sheet_music_free.pdf, https://uploads.strikinglycdn.com/files/73429591-d0b3-4754-af18-801435fa20dc/39516806340.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=download%20god%20of%20egypt%20full%20movie%20in
- https://uploads.strikinglycdn.com/files/75e56fa3-c855-4248-aeda-d3efe733f293/the_greatest_showman_piano_sheet_music_free.pdf
- https://uploads.strikinglycdn.com/files/73429591-d0b3-4754-af18-801435fa20dc/39516806340.pdf
- https://uploads.strikinglycdn.com/files/ae94ce07-4898-47b0-8e74-101b71e05465/86077616090.pdf
- https://uploads.strikinglycdn.com/files/52faf1ca-8977-4a32-823e-d0001c9db1eb/83670649683.pdf
- https://cdn-cms.f-static.net/uploads/4374360/normal_5f89222a60e5e.pdf
- https://cdn-cms.f-static.net/uploads/4378628/normal_5f8a4eaf480dc.pdf
- https://cdn-cms.f-static.net/uploads/4378605/normal_5f8b239b751f0.pdf
- https://cdn-cms.f-static.net/uploads/4365624/normal_5f88c0e9e9eff.pdf
- https://cdn-cms.f-static.net/uploads/4370740/normal_5f8be217d35c8.pdf
- https://cdn-cms.f-static.net/uploads/4377642/normal_5f8be4403a297.pdf
- https://cdn-cms.f-static.net/uploads/4370062/normal_5f8815d1caf7c.pdf
- https://cdn-cms.f-static.net/uploads/4383128/normal_5f8b79324ae1e.pdf
- https://cdn-cms.f-static.net/uploads/4374852/normal_5f89bad02bc92.pdf
- https://uploads.strikinglycdn.com/files/d7fcc004-588e-433e-8dd6-6a8ae18e2c88/sululufepumi.pdf
- https://uploads.strikinglycdn.com/files/ff895427-b9b8-4854-b0af-b4e96133b1c7/jezalovumerutexegirevaxed.pdf
- https://uploads.strikinglycdn.com/files/892c563e-c902-44b5-b4a0-3fc974fde7c6/kuboxaximadiwigisu.pdf
- https://cdn-cms.f-static.net/uploads/4376086/normal_5f8a441dd0459.pdf
- https://cdn-cms.f-static.net/uploads/4366980/normal_5f874fe42acb1.pdf
- https://cdn-cms.f-static.net/uploads/4383136/normal_5f8c748606342.pdf
- https://cdn-cms.f-static.net/uploads/4379030/normal_5f8a586970d17.pdf
- https://wedebiki.weebly.com/uploads/1/3/0/9/130969436/witowuje_fumegafukusat.pdf
- https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/6204283.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/xelikanotuzifaja.pdf
- https://bilewobadazape.weebly.com/uploads/1/3/2/6/132695578/xagolopom.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- wedebiki.weebly.com
- nukevokisoget.weebly.com
- fijojonibiw.weebly.com
- bilewobadazape.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report