SUSPICIOUS — nitivetivezuzakol.pdf
SUSPICIOUS — nitivetivezuzakol.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d925ef0df0b98a25b6f0b4134ca18f19321b1f42626c1fbc9d0d59888d53e8ed - SHA-1:
ab5980c9b16c6e5ba514bf6d8ab1f34b17c1567d - MD5:
079bd1aee189a08a9264ca18b8492c6a - ssdeep:
768:9gGzpDU5YBDaEkllJlWtfrDmeueM3+Yk3ZNGfd2rBKfRxX15w5Pgil:+GFASDaEkKtfehdk37EmKfvw5Pgil - TLSH:
T173339DF311A7EE9C7A87AF035EE615499149A78C3032E36855C8776CC4BC3BD2D50AA0 - Submitted as: nitivetivezuzakol.pdf
- File type: pdf · Size: 51900 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=outlining+the+constitution%2527s+six+big+ideas+answers, http://files.templeofthedog.ca/uploads/1/3/1/6/131636890/2267704.pdf, http://files.gofrostyourselfedibleimages.com/uploads/1/3/0/9/130969896/2852816.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=outlining+the+constitution%2527s+six+big+ideas+answers
- http://files.templeofthedog.ca/uploads/1/3/1/6/131636890/2267704.pdf
- http://files.gofrostyourselfedibleimages.com/uploads/1/3/0/9/130969896/2852816.pdf
- http://files.techniac.com/uploads/1/3/1/4/131452733/5ad121692b786.pdf
- https://uploads.strikinglycdn.com/files/33024810-6d0b-4d4b-8578-28d53e50a81f/28100620216.pdf
- https://uploads.strikinglycdn.com/files/0c828059-9a1b-4ba0-acf7-a9c141568076/90383227286.pdf
- https://uploads.strikinglycdn.com/files/1ba6b31c-616e-4186-8362-e908ba941924/59320594670.pdf
- https://uploads.strikinglycdn.com/files/d2be3ed6-7093-48c5-8b54-cfe895f1f899/40089168098.pdf
- http://goxumomun.peaksoap.com/uploads/1/3/1/8/131856080/lowidelij_walopetijuwaper_sufured_labidoletib.pdf
- http://vutezizad.paulwoottenbooks.com/uploads/1/3/2/6/132683289/lepijir.pdf
- http://files.theorderlynest.com/uploads/1/3/1/3/131380848/kasij_rubowosomedi_mawuvi_lezuxu.pdf
- http://files.wisdomgap.org/uploads/1/3/1/3/131397973/7186912.pdf
- http://lelenon.eestilodevida.com/uploads/1/3/2/7/132740482/4502a203.pdf
- https://uploads.strikinglycdn.com/files/cc6e04f1-def4-45d5-b460-e117359f78de/muxolezetozojisigate.pdf
- https://uploads.strikinglycdn.com/files/4321480a-ba0c-42c4-8c13-f2106e28ee37/31985386310.pdf
- https://uploads.strikinglycdn.com/files/3b503359-1e3a-479a-b70e-22528232b83a/30095796851.pdf
- https://uploads.strikinglycdn.com/files/8c45ec3b-8b47-4724-8ea7-bf26ea91d5b7/tesunoxotisumasivakofaxi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.templeofthedog.ca
- files.gofrostyourselfedibleimages.com
- files.techniac.com
- uploads.strikinglycdn.com
- goxumomun.peaksoap.com
- vutezizad.paulwoottenbooks.com
- files.theorderlynest.com
- files.wisdomgap.org
- lelenon.eestilodevida.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report