SUSPICIOUS — tevikinozutibokero.pdf
SUSPICIOUS — tevikinozutibokero.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
8997f2abff9a78e6dfc8449055cb634acb810afb066a023837817ca0ebcb1582 - SHA-1:
c3986b7189cd37019dc78699bc4a378e8577a590 - MD5:
cbe5a456f9cc54065f0febe08984e6dc - ssdeep:
768:cgGzpDFa8PmnJy0+W++saLmbVEoiGHHuHHHHHHHqHHWEkLE5xOFiend9DyKbX5NI:5GF5gY1ZEoi0xOddl7zsNwHiNA0D - TLSH:
T174329EF35197DD8D7AC6AB03AEEB0165104AD78C6223A2A058C8773CD4BD6FDAD40D60 - Submitted as: tevikinozutibokero.pdf
- File type: pdf · Size: 47118 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=quick+shortcut+maker+v.2.0.0+apk+free+download, https://uploads.strikinglycdn.com/files/ac66e748-78be-45a5-9cd7-a58606291689/devemopafu.pdf, https://uploads.strikinglycdn.com/files/352f1eb2-2602-4ded-a11a-16a50fff3b88/94947457972.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=quick+shortcut+maker+v.2.0.0+apk+free+download
- https://uploads.strikinglycdn.com/files/ac66e748-78be-45a5-9cd7-a58606291689/devemopafu.pdf
- https://uploads.strikinglycdn.com/files/352f1eb2-2602-4ded-a11a-16a50fff3b88/94947457972.pdf
- https://uploads.strikinglycdn.com/files/f45da017-f3ca-4581-8bb0-f24dfd409c8f/69210576612.pdf
- https://uploads.strikinglycdn.com/files/1fb5d4a4-d09e-4440-9e79-1411bb1dd4c1/1327917689.pdf
- https://uploads.strikinglycdn.com/files/fc4ce07d-d608-4a65-a469-9e05618fe7e5/sixuk.pdf
- http://lesawu.cdnchiropracticwellness.com/uploads/1/3/0/8/130813612/ramalowowiw.pdf
- https://cdn.shopify.com/s/files/1/0432/0044/6626/files/tales_of_symphonia_gamecube_gameplay.pdf
- https://cdn.shopify.com/s/files/1/0485/0696/2075/files/pibitagexezen.pdf
- https://cdn.shopify.com/s/files/1/0492/8611/9580/files/dna_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0434/5289/1297/files/56315551202.pdf
- https://site-1037129.mozfiles.com/files/1037129/xelukokizamas.pdf
- https://site-1036965.mozfiles.com/files/1036965/28757620605.pdf
- https://site-1042832.mozfiles.com/files/1042832/2603568182.pdf
- https://site-1037867.mozfiles.com/files/1037867/35936846509.pdf
- https://site-1048471.mozfiles.com/files/1048471/pafufopumivowipigudamo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- lesawu.cdnchiropracticwellness.com
- cdn.shopify.com
- site-1037129.mozfiles.com
- site-1036965.mozfiles.com
- site-1042832.mozfiles.com
- site-1037867.mozfiles.com
- site-1048471.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report