MALICIOUS — zigozip.pdf
MALICIOUS — zigozip.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0f41143c22c23f86b3ca37d725b3ae47844c12050e9b49cd253af205359806d9 - SHA-1:
87d6dad2ab2cf839d77ae1b05cc90b94f0e25d87 - MD5:
d12a5fafeca8bc602075d17249e9f306 - ssdeep:
768:o0gGzpDiXszxUwCGCAWkYG+HblhqSGTvVcdevgm82NOJq8MGwsXXu8kSNq+03uAu:IGF+ExuAWJHbKSGD+corIOJqR5sXe8ke - TLSH:
T17D329EF350A7ED8C3A8A9B079DB315A12149C38CA133A7A0489CB72DD1BC57DBE10931 - Submitted as: zigozip.pdf
- File type: pdf · Size: 46344 bytes
- Verdict: malicious (89/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 89/100 is the fusion of 8 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ggtraff.ru/strik?keyword=calculus+early+transcendental+functions+6th+edition+solutions+manual+pdf, https://uploads.strikinglycdn.com/files/9f6fd2f0-269d-40df-9ad8-5e192fa55da3/24176647499.pdf, https://uploads.strikinglycdn.com/files/5b5bc629-7db9-4a62-9e05-044881ce590f/retenonodozopasalejeruxuz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 10 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
994 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- searchapp.bundleassets.example
- teams.cloud.microsoft
- inference.location.live.net
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 192.168.122.112
- 23.40.52.209
- 23.11.37.157
- 20.190.167.150
- 142.251.42.110
- 52.123.252.215
- 52.123.252.213
- 20.42.179.204
- 74.178.76.128
- 23.33.238.119
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://ggtraff.ru/strik?keyword=calculus+early+transcendental+functions+6th+edition+solutions+manual+pdf
- https://uploads.strikinglycdn.com/files/9f6fd2f0-269d-40df-9ad8-5e192fa55da3/24176647499.pdf
- https://uploads.strikinglycdn.com/files/5b5bc629-7db9-4a62-9e05-044881ce590f/retenonodozopasalejeruxuz.pdf
- https://uploads.strikinglycdn.com/files/d9add757-aa92-4de8-8cc4-5b53f4712860/buvusumipidovum.pdf
- https://uploads.strikinglycdn.com/files/3020493e-4566-48b2-b7b5-f209f7291bc8/60322813979.pdf
- https://uploads.strikinglycdn.com/files/4124c96c-0d58-4e2b-bc1e-cb438e6846de/62902272404.pdf
- https://site-1037164.mozfiles.com/files/1037164/tukupogi.pdf
- https://site-1036728.mozfiles.com/files/1036728/70785524966.pdf
- https://site-1036734.mozfiles.com/files/1036734/57989675890.pdf
- http://mudemugaz.yorkvet.net/uploads/1/3/0/8/130814729/060be40.pdf
- http://vutexi.studiogroovefitness.com/uploads/1/3/0/8/130873982/garosop.pdf
- http://lumopirol.octobermoon.shop/uploads/1/3/1/8/131871768/27896453ea.pdf
- http://xesulazez.pyrographystore.com/uploads/1/3/1/4/131452922/3113384.pdf
- http://files.emeraldandvioletstudio.com/uploads/1/3/1/8/131871852/2400929.pdf
- http://pifeli.rocadog.com/uploads/1/3/0/7/130739206/76fb8e9e.pdf
- http://files.testsiteforhsct.info/uploads/1/3/1/6/131636845/rusitelagu_rekep.pdf
- http://pivokirez.lydiafrey.net/uploads/1/3/1/3/131384226/tigiguvekaniz.pdf
- http://files.daytonsockcompany.com/uploads/1/3/1/1/131164236/vawano-kesupapo.pdf
- http://files.ourvillagefarmacy.com/uploads/1/3/0/9/130969054/9811449.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1037164.mozfiles.com
- site-1036728.mozfiles.com
- site-1036734.mozfiles.com
- mudemugaz.yorkvet.net
- vutexi.studiogroovefitness.com
- lumopirol.octobermoon.shop
- xesulazez.pyrographystore.com
- files.emeraldandvioletstudio.com
- pifeli.rocadog.com
- files.testsiteforhsct.info
- pivokirez.lydiafrey.net
- files.daytonsockcompany.com
- files.ourvillagefarmacy.com
- www.w3.org
- purl.org
- ns.adobe.com
Embedded IP addresses
- 52.123.252.215
- 52.123.252.213
- 20.42.179.204
- 74.178.76.128
- 74.178.240.61
- 4.230.171.124
- 162.159.36.2
- 203.26.79.13
- 92.223.78.30
- 135.232.92.34
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report