SUSPICIOUS — zomunevaxima.pdf
SUSPICIOUS — zomunevaxima.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b36ed57056fcb90eb2cba86aa8a1326d9cccbc6463350d611f77bc209a1a7451 - SHA-1:
91243357f7af8cad839d9348eebb019c63a32276 - MD5:
64d2f04e3c2486832deb5175d87eb59f - ssdeep:
768:pgGzpD8pRpx5X9Rc1rxjH7LJ6VelEZuGqanTyKFKF3XjXFq/011jCQlwttm3c:KGFYpRCrFfJnyZuGfyKF43TXeuUQ6ttl - TLSH:
T1CF31AFF79557EC4CBA869B0B9EEA05992189DB4D7032A66048D8372DC4BC7FC7E00631 - Submitted as: zomunevaxima.pdf
- File type: pdf · Size: 41624 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=fun+maths+worksheets+for+grade+3, https://site-1039430.mozfiles.com/files/1039430/61509090547.pdf, https://site-1040129.mozfiles.com/files/1040129/jajatimosuvobekegijidu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=fun+maths+worksheets+for+grade+3
- https://site-1039430.mozfiles.com/files/1039430/61509090547.pdf
- https://site-1040129.mozfiles.com/files/1040129/jajatimosuvobekegijidu.pdf
- https://site-1044117.mozfiles.com/files/1044117/46973560827.pdf
- https://site-1041413.mozfiles.com/files/1041413/74897897647.pdf
- https://uploads.strikinglycdn.com/files/d17126b8-8e99-44d3-a8c0-954baf168e00/juwaratetuxuzimaxarafeko.pdf
- https://uploads.strikinglycdn.com/files/caabd73e-c878-4e8d-9110-82c0666eb9af/9169930874.pdf
- https://cdn.shopify.com/s/files/1/0496/1412/7271/files/current_events_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0483/9407/6312/files/assurance_wireless_phone_manual.pdf
- https://cdn.shopify.com/s/files/1/0496/5990/4163/files/ecological_succession_worksheet_high_school.pdf
- https://cdn.shopify.com/s/files/1/0435/0168/2852/files/guia_portage_fichas.pdf
- https://uploads.strikinglycdn.com/files/5f47c845-f30c-4713-b2a9-22508b7a212b/nijawurisoruker.pdf
- https://uploads.strikinglycdn.com/files/16a32bff-301e-42e1-a75e-978a01614a1c/tifiwopapab.pdf
- https://uploads.strikinglycdn.com/files/0643fcd1-975b-4007-9744-79b2eac562f3/vajuluwonixokelovugizeb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1039430.mozfiles.com
- site-1040129.mozfiles.com
- site-1044117.mozfiles.com
- site-1041413.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report