SUSPICIOUS — tezetut.pdf
SUSPICIOUS — tezetut.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ee81a2dd1799fb422991e2132a460708f860117c76c5773864551d2d666346ef - SHA-1:
7cb72604ad5c50f73e30c2ea142f6c67cbe24f0b - MD5:
0fa056ccb53c95e676a32f88878853cf - ssdeep:
768:1gGzpDgp0LgoMRCPUjup4WRACjkG2IdVfyDYqq/9OdryPBewR+CWcWQbYFKC0E:mGFspdml5kpu7qq/22PBJ+CWwUoC0E - TLSH:
T14B358EF3308BFDCCAA4B5F63799711ADE58DD6C821E65AA100D8B65CC83C2EC6B10561 - Submitted as: tezetut.pdf
- File type: pdf · Size: 59503 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=derivadas%20parciales%20definicion, https://site-1041285.mozfiles.com/files/1041285/tutinosupo.pdf, https://site-1040322.mozfiles.com/files/1040322/gemetidakekuxibabi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=derivadas%20parciales%20definicion
- https://site-1041285.mozfiles.com/files/1041285/tutinosupo.pdf
- https://site-1040322.mozfiles.com/files/1040322/gemetidakekuxibabi.pdf
- https://site-1040878.mozfiles.com/files/1040878/970910360.pdf
- https://uploads.strikinglycdn.com/files/baf4f926-38c2-4162-9406-1a9b2e1bfb7a/zotebokisire.pdf
- https://uploads.strikinglycdn.com/files/cae3d897-8b31-44a1-bbea-bcdcff2d7576/xowigokumadilalonezara.pdf
- https://uploads.strikinglycdn.com/files/b6303db3-df8a-48f3-b013-c2a988361b33/14153768176.pdf
- https://uploads.strikinglycdn.com/files/a961d7fe-6cc5-462e-bd66-56a829474955/45957866182.pdf
- https://cdn.shopify.com/s/files/1/0462/8280/1312/files/mastering_autodesk_inventor_2018_free_download.pdf
- https://cdn.shopify.com/s/files/1/0266/9867/8457/files/sawaxiwaropawitalobevidaf.pdf
- https://cdn.shopify.com/s/files/1/0433/3872/7589/files/rusk_hair_color_guide.pdf
- https://cdn.shopify.com/s/files/1/0499/9161/4614/files/hp_laserjet_1320_driver_windows_7.pdf
- https://cdn.shopify.com/s/files/1/0430/5872/5018/files/zinwell_zat-970a_manual.pdf
- https://cdn.shopify.com/s/files/1/0497/4693/5969/files/because_i_could_not_stop_for_death_questions.pdf
- https://uploads.strikinglycdn.com/files/163136b1-723a-41b6-b119-0d2f2cd7225d/nezizemawixudizo.pdf
- https://uploads.strikinglycdn.com/files/d73ca38d-dd78-4db2-a7f2-892e94c4e83e/26933441457.pdf
- https://uploads.strikinglycdn.com/files/9a055fda-a427-42b6-9a6b-56598bb374b6/xetosisop.pdf
- https://uploads.strikinglycdn.com/files/306b9430-f8f7-4c71-addf-906901d61a83/93671605750.pdf
- https://uploads.strikinglycdn.com/files/38438c66-595b-4bdb-9476-f43f865657e3/fusoxidefukilikuduv.pdf
- https://uploads.strikinglycdn.com/files/680523f8-f389-42b2-86ca-75191972696f/lobatorodesuwuvojuw.pdf
- https://uploads.strikinglycdn.com/files/1a1fa3e3-f71c-41b1-a444-a3bb1b23d278/rozadolitudo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- site-1041285.mozfiles.com
- site-1040322.mozfiles.com
- site-1040878.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report