SUSPICIOUS — zelufigav.pdf
SUSPICIOUS — zelufigav.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
7b7f4e269fde6a9772f74fc8dbc802848f43533f6e4d7686129f33f15900bf86 - SHA-1:
43d0e283a1311b14bae56295c85331667fd01cd7 - MD5:
28712cc358b828d43835095d72ca18f3 - ssdeep:
768:7gGzpDypZVBRo4wY6wmI3H8RcXs0r23d+3pEo03GTXDkDUPCVn:EGFmpDo4IwmIsRp0r23dEpEodfkD9Vn - TLSH:
T10633BFF300DBED8C76CA671398BB10696189C38C623AD76499A8777CC47C6BD3E10960 - Submitted as: zelufigav.pdf
- File type: pdf · Size: 48377 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=c%20templates%20the%20complete%20guide, https://uploads.strikinglycdn.com/files/bfd5100d-9c71-405c-8401-3b17803b9020/turuzegovobomixuzidazan.pdf, https://uploads.strikinglycdn.com/files/8b234d85-b2c9-4f42-9ae8-68c4409010a5/xixafajogul.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=c%20templates%20the%20complete%20guide
- https://s3.amazonaws.com/jamokaroxoj/ammonia_gas_sensor.pdf
- https://s3.amazonaws.com/kavitokolezub/libegusufagaguvazowasa.pdf
- https://s3.amazonaws.com/kavitokolezub/parametric_and_nonparametric_analysis.pdf
- https://uploads.strikinglycdn.com/files/bfd5100d-9c71-405c-8401-3b17803b9020/turuzegovobomixuzidazan.pdf
- https://uploads.strikinglycdn.com/files/8b234d85-b2c9-4f42-9ae8-68c4409010a5/xixafajogul.pdf
- https://s3.amazonaws.com/sugaguxagu/mekujefakizamekuwo.pdf
- https://s3.amazonaws.com/zuxadol/joint_of_multivariate_normal_distribution.pdf
- https://s3.amazonaws.com/henghuili-files2/58932034354.pdf
- https://uploads.strikinglycdn.com/files/5cffc5e8-dfca-4b99-869d-8069d58d9ac2/tuzixuzenipirurem.pdf
- https://uploads.strikinglycdn.com/files/81b0fe4c-edff-4382-8a5d-e4addcb32ef4/pivakelegawofolujarim.pdf
- https://uploads.strikinglycdn.com/files/67e74bf7-776f-491e-aff0-c36f51810988/58185169299.pdf
- https://uploads.strikinglycdn.com/files/0615e2ee-70e0-46cd-8aab-52324c57874a/19494322532.pdf
- https://uploads.strikinglycdn.com/files/3c92d53e-4c1a-47c0-be97-dee1495fba10/wefuninuladusodudotuloj.pdf
- https://uploads.strikinglycdn.com/files/f7e67584-a263-4a4f-a9cb-6bccea84be2d/kizomuxo.pdf
- https://uploads.strikinglycdn.com/files/470f0f05-5bac-4973-b95f-bc35197e039e/56199110355.pdf
- https://uploads.strikinglycdn.com/files/efa05928-db62-4346-aaf7-f5f9cf102d90/lenujalaz.pdf
- https://sisodiwitamusoz.weebly.com/uploads/1/3/2/6/132681746/bomasoxitav.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/9031774.pdf
- https://mesipaku.weebly.com/uploads/1/3/1/3/131383407/vevuxa_begebodasukevu_movaxumage_xobamovif.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- sisodiwitamusoz.weebly.com
- vuxozajuje.weebly.com
- mesipaku.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report