SUSPICIOUS — zegavisosowajudozapudu.pdf
SUSPICIOUS — zegavisosowajudozapudu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
886a4f5436b06de95069023aa80f9b43a1c59ad4d9c64d1d907e4d3bb9d48617 - SHA-1:
982bd1b89e19910094d8207b9a9cfe6ac9ae20f4 - MD5:
1222a55cbdd83b635d86f6c5486fe3b0 - ssdeep:
1536:AGF8KeHoN1u7VJIG2ASokEtf4QaiWnQDuIO3:NF8YuB2FASoztf4Jeu5 - TLSH:
T1B033BFF31097EC8C7BCA8B036DBA256915C6C7896136E7A0448CB36DC47C7BDAE50890 - Submitted as: zegavisosowajudozapudu.pdf
- File type: pdf · Size: 49594 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=cheat+engine+dawn+of+war+2, http://feferisav.nettletonband.com/uploads/1/3/0/7/130776321/445d93.pdf, http://dideta.binyacatalog.com/uploads/1/3/2/3/132303195/58937.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=cheat+engine+dawn+of+war+2
- http://feferisav.nettletonband.com/uploads/1/3/0/7/130776321/445d93.pdf
- http://dideta.binyacatalog.com/uploads/1/3/2/3/132303195/58937.pdf
- http://gapimep.dryanbuford.com/uploads/1/3/0/9/130969352/jemusibegoje_kudipituponari_rowalez.pdf
- http://bukonag.concertsbythecreek.com/uploads/1/3/2/3/132303168/bulejujez.pdf
- http://poxizi.luvtheview.com/uploads/1/3/1/4/131406286/xufifodelonula.pdf
- https://site-1039897.mozfiles.com/files/1039897/15193910950.pdf
- https://site-1038948.mozfiles.com/files/1038948/gapudoxarigogarufofemeg.pdf
- https://site-1039885.mozfiles.com/files/1039885/67963492464.pdf
- https://site-1041075.mozfiles.com/files/1041075/kefixabibufamaluragilema.pdf
- https://cdn.shopify.com/s/files/1/0434/4823/8241/files/90014891052.pdf
- https://cdn.shopify.com/s/files/1/0434/5335/0040/files/what_time_is_the_husker_spring_game_2019.pdf
- https://site-1038431.mozfiles.com/files/1038431/kevegimoturakatawiv.pdf
- https://site-1037824.mozfiles.com/files/1037824/92922368111.pdf
- https://site-1036818.mozfiles.com/files/1036818/97523522400.pdf
- https://site-1036685.mozfiles.com/files/1036685/76527639279.pdf
- http://bltlly.com/152kdq
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- feferisav.nettletonband.com
- dideta.binyacatalog.com
- gapimep.dryanbuford.com
- bukonag.concertsbythecreek.com
- poxizi.luvtheview.com
- site-1039897.mozfiles.com
- site-1038948.mozfiles.com
- site-1039885.mozfiles.com
- site-1041075.mozfiles.com
- cdn.shopify.com
- site-1038431.mozfiles.com
- site-1037824.mozfiles.com
- site-1036818.mozfiles.com
- site-1036685.mozfiles.com
- bltlly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report