SUSPICIOUS — zolejotuluton.pdf
SUSPICIOUS — zolejotuluton.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ae1a6fac2f1376a01bc9fad36af9d17111e0943f96250a96caa01cede6767a17 - SHA-1:
971c05fb9ea1ed116cc9382531b22719ef5b0048 - MD5:
b0c1fc7ff7a15dc4b9b11e0b8e28c04c - ssdeep:
768:ygGzpD4pvOAJpNty1AD/c3uDcjiIFaK0mzro574SzI0nF33MvXN40:vGF8pvOAf3IFaEwESz1F3MvXN40 - TLSH:
T175306CF340A7ED4C6986EB13AEBE195C5189D7886133A360449C76ACD47C2BD3F40AA0 - Submitted as: zolejotuluton.pdf
- File type: pdf · Size: 38900 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=calculo%20tomo%201%20larson%2010%20edicion%20pdf, https://uploads.strikinglycdn.com/files/adaea0be-fd8e-4261-87a0-0599df585059/18627411997.pdf, https://uploads.strikinglycdn.com/files/87d8c558-5e35-4d0e-ab60-4f19cb0119ed/wixukotesuzixoxetewak.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=calculo%20tomo%201%20larson%2010%20edicion%20pdf
- https://uploads.strikinglycdn.com/files/adaea0be-fd8e-4261-87a0-0599df585059/18627411997.pdf
- https://uploads.strikinglycdn.com/files/87d8c558-5e35-4d0e-ab60-4f19cb0119ed/wixukotesuzixoxetewak.pdf
- https://uploads.strikinglycdn.com/files/82f99504-b16f-4101-bd7a-9ddcdcc77592/84765003051.pdf
- https://uploads.strikinglycdn.com/files/8dd5139f-0527-4e6b-bd98-56dc16a1611a/zufixiwigukowadogibadirot.pdf
- https://cdn-cms.f-static.net/uploads/4373992/normal_5f897c9c6b29d.pdf
- https://cdn-cms.f-static.net/uploads/4377679/normal_5f8a145f80037.pdf
- https://cdn.shopify.com/s/files/1/0502/5556/0872/files/abruptio_placentae_acog.pdf
- https://cdn.shopify.com/s/files/1/0476/7481/8726/files/kakobu.pdf
- https://cdn.shopify.com/s/files/1/0431/7750/9020/files/38433977417.pdf
- https://nubojubixuxo.weebly.com/uploads/1/3/1/4/131410311/nonotanesajajabad.pdf
- https://xetutinafo.weebly.com/uploads/1/3/0/7/130775845/1817f.pdf
- https://cdn.shopify.com/s/files/1/0482/1067/3821/files/conditionals_advanced.pdf
- https://cdn.shopify.com/s/files/1/0484/1226/2552/files/watujigan.pdf
- https://cdn.shopify.com/s/files/1/0484/2730/3080/files/raxularitutefurufanivuwo.pdf
- https://cdn.shopify.com/s/files/1/0496/1714/1909/files/c-value_paradox_refers_to_the_presence_of.pdf
- https://cdn.shopify.com/s/files/1/0497/5217/8849/files/tapugedolexulivanus.pdf
- https://uploads.strikinglycdn.com/files/685058ba-818f-499b-b9f4-38526dde0159/fitekika.pdf
- https://uploads.strikinglycdn.com/files/f3dba7e4-179d-4cc3-86b5-e0341d89c54c/mutekivokajorol.pdf
- https://uploads.strikinglycdn.com/files/13d6f577-cbd5-488d-a66d-206e2309847b/pepitafetudokolevu.pdf
- https://uploads.strikinglycdn.com/files/b7c6759f-c89b-41d9-9c2e-dfe6a3a2f541/rovorufabixulolasopi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- nubojubixuxo.weebly.com
- xetutinafo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report