SUSPICIOUS — zukuti.pdf
SUSPICIOUS — zukuti.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e25f47e391b29d540e32e08b14d75dc86acea345e568ffa877248a653512a4a7 - SHA-1:
1260720df0653a0cd4df6c7260951f412f122c4f - MD5:
fffd1742952e98f909638089d7e04891 - ssdeep:
768:5gGzpDqo85eOa3Zd6XqVR0llvriZ+39lzwaLvYhFEIEbcLn9BSOKnxgici7i4:6GFmoXY+Z+7ztY3bEbin9sH/ci7i4 - TLSH:
T15A339FF3459BECCD7B8A9F035DAA15192286D78C3037999444C87B6CC4BC6FC6E01A62 - Submitted as: zukuti.pdf
- File type: pdf · Size: 48987 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=fusion+360+assembly+tutorial+pdf, http://luxawa.walkonmeflooring.com/uploads/1/3/2/6/132682137/moregazap.pdf, http://luvobopa.vasalou.net/uploads/1/3/0/8/130813115/8802676.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=fusion+360+assembly+tutorial+pdf
- http://luxawa.walkonmeflooring.com/uploads/1/3/2/6/132682137/moregazap.pdf
- http://luvobopa.vasalou.net/uploads/1/3/0/8/130813115/8802676.pdf
- http://xabumi.seymourdachshunds.com/uploads/1/3/2/3/132302870/dosamasekixuvev.pdf
- http://jowoxefum.clayshootingdevon.co.uk/uploads/1/3/2/8/132814838/7340665.pdf
- https://cdn.shopify.com/s/files/1/0485/7934/6592/files/bizoxaz.pdf
- http://files.airbrushingwood.com/uploads/1/3/1/0/131070792/c86f5.pdf
- http://files.owenhartfoundationmovie.com/uploads/1/3/1/4/131454766/jegozabunadugil-zujixaze-norubudemojego-kivonikomejono.pdf
- http://files.alissahartenbaum.com/uploads/1/3/1/6/131637881/72efd0455b0d373.pdf
- https://cdn.shopify.com/s/files/1/0438/0812/9185/files/simple_compound_and_complex_sentences_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0499/9407/2214/files/48077626079.pdf
- https://cdn.shopify.com/s/files/1/0481/3819/1015/files/ferret_rescue_indiana.pdf
- https://cdn.shopify.com/s/files/1/0430/1049/0519/files/summon_lesser_demons_options.pdf
- https://cdn.shopify.com/s/files/1/0438/2674/1405/files/91424340941.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- luxawa.walkonmeflooring.com
- luvobopa.vasalou.net
- xabumi.seymourdachshunds.com
- jowoxefum.clayshootingdevon.co.uk
- cdn.shopify.com
- files.airbrushingwood.com
- files.owenhartfoundationmovie.com
- files.alissahartenbaum.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report