SUSPICIOUS — zumutabifunuwu.pdf
SUSPICIOUS — zumutabifunuwu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ce685874692d92c5ba2d47cca1a8da18bfe36243aabb01ceb68b7ae3471201c4 - SHA-1:
ad43231622afc09442382681dcc1838e9532f311 - MD5:
ea46b2c44ed658067c105e96aba6450f - ssdeep:
768:TgGzpD410Dedc0NpfKx0RcjyfGoYgb59+sZbKgDqsDGSXgXLGQtctYPtz:sGFceDedc0q6cgfDiLG7tmtz - TLSH:
T18A328DF310B3ED4C7B8BAB53BDE62529914EC7886072DA744888772CC4BC6BD6E40954 - Submitted as: zumutabifunuwu.pdf
- File type: pdf · Size: 44707 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=motul%20300v%200w40%20pdf, https://uploads.strikinglycdn.com/files/b3e5a475-f966-4969-999c-38f41cc60ae9/que_hacer_si_mi_media_naranja_es_toronja_descargar_gratis.pdf, https://uploads.strikinglycdn.com/files/8d48f247-3dbc-49cf-8bbe-90748006616d/34292970018.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=motul%20300v%200w40%20pdf
- https://uploads.strikinglycdn.com/files/b3e5a475-f966-4969-999c-38f41cc60ae9/que_hacer_si_mi_media_naranja_es_toronja_descargar_gratis.pdf
- https://uploads.strikinglycdn.com/files/8d48f247-3dbc-49cf-8bbe-90748006616d/34292970018.pdf
- https://uploads.strikinglycdn.com/files/9de5d996-e582-4a34-8774-b9fc2b6a7fd0/python_artificial_intelligence_tutorial.pdf
- https://uploads.strikinglycdn.com/files/26773bc7-8d85-4c16-a3f5-5c20815ce99c/pearson_world_geography.pdf
- https://uploads.strikinglycdn.com/files/51e17001-c82b-43b4-9b49-3cc30dec6300/61158834433.pdf
- https://cdn.shopify.com/s/files/1/0433/9279/4773/files/columbus_dispatch_voters_guide_2020.pdf
- https://cdn.shopify.com/s/files/1/0482/1542/5176/files/manual_de_tai_chi_espaol_gratis.pdf
- https://uploads.strikinglycdn.com/files/d5842d65-ce0b-4392-833f-ff07f3be1285/57333849177.pdf
- https://uploads.strikinglycdn.com/files/7d049a3d-1020-41f5-9d17-84c70885437e/wozevipe.pdf
- https://cdn-cms.f-static.net/uploads/4375095/normal_5f911b458effa.pdf
- https://cdn-cms.f-static.net/uploads/4370543/normal_5f8b0d5f9fc42.pdf
- https://uploads.strikinglycdn.com/files/453698be-fb53-4f90-aaec-82e791efadc4/Hdm_balantlar_ile_2_Portlu_kablo.pdf
- https://uploads.strikinglycdn.com/files/bff21e71-9585-4488-9cab-50f63f31c830/togimoziruw.pdf
- https://uploads.strikinglycdn.com/files/8b44d4c4-b12a-4025-9983-33dd6fbb7e53/53980630578.pdf
- https://uploads.strikinglycdn.com/files/122a00ea-a8b3-44c3-8d8c-c7672fb733c3/60146857176.pdf
- https://cdn-cms.f-static.net/uploads/4369309/normal_5f911927776c2.pdf
- https://cdn-cms.f-static.net/uploads/4371543/normal_5f93b44bbd1b0.pdf
- https://cdn-cms.f-static.net/uploads/4368237/normal_5f920fae93733.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report