SUSPICIOUS — zugilafoz-melowotalixu.pdf
SUSPICIOUS — zugilafoz-melowotalixu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
8c6eaa01499743feab7956cd5ab3fe548a5403a6edbac65264c8cacfad34ab18 - SHA-1:
c883483705b7256e5371f5ca7d460162675d4289 - MD5:
6fe7c5ccb60f4e52b96a4c9ed39cdfac - ssdeep:
768:LgGzpDkeEK64jv23/zsoIxFktg78lfdvCn0YhmqnxeNKstY/okvPEEgPxcLwD:0GFYeGU0YIqxelW/G5OwD - TLSH:
T1D6329DF31093DD4C7A8A9B13ACFB106A1449D7886236A7A4449C7B2DC57C7BDBE10A60 - Submitted as: zugilafoz-melowotalixu.pdf
- File type: pdf · Size: 43929 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=how%20to%20install%20parking%20brake%20bypass%20pioneer, https://cdn-cms.f-static.net/uploads/4366369/normal_5f876b60dad09.pdf, https://cdn-cms.f-static.net/uploads/4367277/normal_5f873934c2f44.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=how%20to%20install%20parking%20brake%20bypass%20pioneer
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f876b60dad09.pdf
- https://cdn-cms.f-static.net/uploads/4367277/normal_5f873934c2f44.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f8744203d5af.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f87eefa9cc78.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f8759d6bb1c3.pdf
- https://cdn-cms.f-static.net/uploads/4366654/normal_5f871da700777.pdf
- https://cdn.shopify.com/s/files/1/0496/0967/0820/files/response_to_stimuli_characteristics_of_life.pdf
- https://cdn.shopify.com/s/files/1/0436/6286/8633/files/the_man_in_the_water_essay.pdf
- https://cdn.shopify.com/s/files/1/0497/4624/7833/files/trish_austin_and_ally_now.pdf
- https://cdn.shopify.com/s/files/1/0499/8683/0496/files/88724379558.pdf
- https://cdn.shopify.com/s/files/1/0436/3157/5198/files/sheryl_sandberg_lean_in_for_graduates.pdf
- https://uploads.strikinglycdn.com/files/df004bf4-4bff-4bc8-ba15-4d82dd945d93/68470696689.pdf
- https://uploads.strikinglycdn.com/files/b591ecf2-eaa8-41ec-8b61-ad3be2b35a5a/79010965489.pdf
- https://uploads.strikinglycdn.com/files/64604f2b-a1c5-4dd9-8545-7b6d5e77b8f9/75609551972.pdf
- https://uploads.strikinglycdn.com/files/fd53ecf7-fc48-4526-9d36-caab5f025506/76971095130.pdf
- https://uploads.strikinglycdn.com/files/5d7a0c2d-ad1b-4784-b14b-f9852bed32f8/11237570411.pdf
- https://cdn.shopify.com/s/files/1/0495/6150/1848/files/wikudapi.pdf
- https://cdn.shopify.com/s/files/1/0496/0118/3896/files/guxonufuvubupigasoxof.pdf
- https://cdn.shopify.com/s/files/1/0492/9218/1660/files/11486165702.pdf
- https://cdn.shopify.com/s/files/1/0437/3302/4929/files/2014_ap_biology_free_response_questions.pdf
- https://cdn.shopify.com/s/files/1/0477/4353/3212/files/modot_traffic_cameras_rolla_mo.pdf
- https://cdn.shopify.com/s/files/1/0435/9100/8418/files/aapc_cpc_study_guide_2016.pdf
- https://cdn.shopify.com/s/files/1/0483/8791/5925/files/barcol_art_festival_staten_island_2018.pdf
- https://cdn.shopify.com/s/files/1/0499/8037/5211/files/2334411401.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.google.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report