SUSPICIOUS — zojefokaduve.pdf
SUSPICIOUS — zojefokaduve.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c4c961bec2d7f59dc197a7e29de08ac17d45ca0372d2432f43d75517f18cf9c0 - SHA-1:
3b6de1417b3bff3bbe9693a6f3f7e19d153fdbf4 - MD5:
0a30ef07e33c078c882f1adae6409ed7 - ssdeep:
768:LgGzpDvkpvW2PyTDDVG+SjVAwBvM0XXupKYdJrQZdxr:0GFopu2aQxM0Hm/rQZdxr - TLSH:
T19F317DF354E3EC4C7E8A5B03ADA71155618AC38D7137AB904898376DC8BCAFD6E10960 - Submitted as: zojefokaduve.pdf
- File type: pdf · Size: 40254 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=loco%20revue%20pdf, https://site-1043404.mozfiles.com/files/1043404/rolunem.pdf, https://site-1039279.mozfiles.com/files/1039279/bimajefis.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=loco%20revue%20pdf
- https://site-1043404.mozfiles.com/files/1043404/rolunem.pdf
- https://site-1039279.mozfiles.com/files/1039279/bimajefis.pdf
- https://site-1038349.mozfiles.com/files/1038349/lidevizaw.pdf
- https://site-1043130.mozfiles.com/files/1043130/13488044959.pdf
- https://site-1038729.mozfiles.com/files/1038729/35276335517.pdf
- https://site-1039386.mozfiles.com/files/1039386/21289963151.pdf
- https://site-1043199.mozfiles.com/files/1043199/retukepuniwu.pdf
- https://site-1042355.mozfiles.com/files/1042355/44060276096.pdf
- https://uploads.strikinglycdn.com/files/9a7f1920-58b0-4925-b347-3ef484937cae/75418339619.pdf
- https://uploads.strikinglycdn.com/files/cedf132a-df12-418a-b370-25fa3ec08bf2/gazixaxotulipewifu.pdf
- https://uploads.strikinglycdn.com/files/4a42d332-ceb9-496a-b5aa-80c509473875/wovajaturiwufededama.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279037.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/3373854.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/bibesekukemugedovofa.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/3029889.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/461c37c449b0.pdf
- https://cdn.shopify.com/s/files/1/0485/2167/4914/files/banjo-kazooie_nuts_and_bolts_tower_codes.pdf
- https://cdn.shopify.com/s/files/1/0481/1882/5123/files/27868573494.pdf
- https://uploads.strikinglycdn.com/files/2b002373-fbd8-4417-a2ba-572f3b68652d/51484461108.pdf
- https://uploads.strikinglycdn.com/files/13d53cd5-e362-4dbf-843f-33ff29fbb107/62422398276.pdf
- https://uploads.strikinglycdn.com/files/9e79bb1c-a68c-4382-9363-2fd54a9471ee/vuziponuwop.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- site-1043404.mozfiles.com
- site-1039279.mozfiles.com
- site-1038349.mozfiles.com
- site-1043130.mozfiles.com
- site-1038729.mozfiles.com
- site-1039386.mozfiles.com
- site-1043199.mozfiles.com
- site-1042355.mozfiles.com
- uploads.strikinglycdn.com
- fijojonibiw.weebly.com
- xojerajap.weebly.com
- jemiwuwavaza.weebly.com
- jakedekokobara.weebly.com
- wepugimi.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report