SUSPICIOUS — zefujozazoxobugoduzo.pdf
SUSPICIOUS — zefujozazoxobugoduzo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8978bd1840ebab6349a2c69eec6cd29f8b9ca81f8ab05b70ba5a6c73e6a6d43c - SHA-1:
5ba4becbeee4265186694158651e54d518bfaa56 - MD5:
9bd03d46463849419517ae427336d1ca - ssdeep:
768:5gGzpDk0tEp/6iy5lE5R23/t0biEHeOBJf/KV+Gv3EdyNmk+Yfn51bfEEPN1kk5:6GF4PpCr8RjbzeOvXKV/3EdGpPN1kk5 - TLSH:
T17B33BFF35067DC8CBAC6EB035EAA245D608AD78C6132967409D8376DC0BC3BD6E50A60 - Submitted as: zefujozazoxobugoduzo.pdf
- File type: pdf · Size: 48150 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=mac+terminal+shortcut+pdf, https://site-1038684.mozfiles.com/files/1038684/96251194393.pdf, https://site-1036685.mozfiles.com/files/1036685/xumetenixokigavexizije.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=mac+terminal+shortcut+pdf
- https://site-1038684.mozfiles.com/files/1038684/96251194393.pdf
- https://site-1036685.mozfiles.com/files/1036685/xumetenixokigavexizije.pdf
- https://site-1041212.mozfiles.com/files/1041212/tidejoveduzekemena.pdf
- https://site-1038442.mozfiles.com/files/1038442/38839861027.pdf
- https://site-1038407.mozfiles.com/files/1038407/tejuzolegiwowavukidil.pdf
- https://uploads.strikinglycdn.com/files/ffd8e4c5-9e55-4c16-b105-4836b9114b8a/vefebeli.pdf
- https://uploads.strikinglycdn.com/files/86441391-6ec3-42b7-a988-b6b77d8195eb/xosifajikabuvabageladex.pdf
- https://uploads.strikinglycdn.com/files/53cd9664-6ae6-4901-8298-1701c348a299/wibulajugabumabaw.pdf
- https://uploads.strikinglycdn.com/files/a93ba740-2325-4e7b-b55d-a77f0a2c0591/85041335773.pdf
- http://xosugate.brooksidepomsky.com/uploads/1/3/0/7/130775350/gawikak.pdf
- http://jitaju.supthecoast.com/uploads/1/3/0/7/130775643/fitejap.pdf
- http://rarafun.therealequestrian.com/uploads/1/3/0/9/130969140/3c86427f02.pdf
- http://nokoz.alyssafamoso.com/uploads/1/3/0/7/130775542/78e97.pdf
- https://site-1036850.mozfiles.com/files/1036850/84204399624.pdf
- https://site-1038675.mozfiles.com/files/1038675/50878539790.pdf
- https://site-1036646.mozfiles.com/files/1036646/93196696346.pdf
- https://site-1039427.mozfiles.com/files/1039427/potalorexodizalawigilasu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1038684.mozfiles.com
- site-1036685.mozfiles.com
- site-1041212.mozfiles.com
- site-1038442.mozfiles.com
- site-1038407.mozfiles.com
- uploads.strikinglycdn.com
- xosugate.brooksidepomsky.com
- jitaju.supthecoast.com
- rarafun.therealequestrian.com
- nokoz.alyssafamoso.com
- site-1036850.mozfiles.com
- site-1038675.mozfiles.com
- site-1036646.mozfiles.com
- site-1039427.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report