SUSPICIOUS — zaxukozegulakapoxofarob.pdf
SUSPICIOUS — zaxukozegulakapoxofarob.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f06a97f5ded1ebf4d85d467a159c7e910df17578d92264359b8a0d20af58f14c - SHA-1:
546d9a8047f76f31c5d3b4f0c087ac05957243c8 - MD5:
0ffeda270c7c3a8a46d3e013aa919803 - ssdeep:
768:33gGzpDu8msVNEf56gIcJK3w0JDo/Seuwgzxn8tZu2kFoFjrIrhA7i:3QGFy8xgsg0FoKeSOtZu1FOIrhA7i - TLSH:
T10331AEF740ABED4D7A86AB0368E90096218DD6882033A6B04DC8737CE47C9FD6F50572 - Submitted as: zaxukozegulakapoxofarob.pdf
- File type: pdf · Size: 41288 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=volume+of+a+cube+worksheets, http://files.vickycavanagh-hodge.com/uploads/1/3/2/6/132696580/e349230d99.pdf, http://files.gracelandsafaris.com/uploads/1/3/0/7/130739373/lojajidokoxi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=volume+of+a+cube+worksheets
- http://files.vickycavanagh-hodge.com/uploads/1/3/2/6/132696580/e349230d99.pdf
- http://files.gracelandsafaris.com/uploads/1/3/0/7/130739373/lojajidokoxi.pdf
- http://files.bbawakeblogs.com/uploads/1/3/1/4/131437268/66807.pdf
- http://dokevi.uccbaycity.org/uploads/1/3/1/3/131378898/a95211a0b17e6e2.pdf
- https://cdn.shopify.com/s/files/1/0486/1866/8192/files/bug_in_a_rug_wilmington_north_carolina.pdf
- http://files.moorlearning.org/uploads/1/3/0/8/130813417/8707663.pdf
- http://rikale.artsoulhealing.com/uploads/1/3/2/3/132303001/5f34f6d4c10.pdf
- http://files.venueonthesquare.com/uploads/1/3/1/6/131606011/6940664.pdf
- https://cdn.shopify.com/s/files/1/0438/8572/3816/files/kobasit.pdf
- https://cdn.shopify.com/s/files/1/0432/7027/5237/files/bone_black_bell_hooks.pdf
- https://cdn.shopify.com/s/files/1/0491/7382/3654/files/the_prince_of_milk_paperback.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.vickycavanagh-hodge.com
- files.gracelandsafaris.com
- files.bbawakeblogs.com
- dokevi.uccbaycity.org
- cdn.shopify.com
- files.moorlearning.org
- rikale.artsoulhealing.com
- files.venueonthesquare.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report