SUSPICIOUS — zenaji.pdf
SUSPICIOUS — zenaji.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
121c538d6e9a1885f6b3f11760df40813a429001079513ce2a80de0625d16a3f - SHA-1:
3ca1968c442416f62179c11ae13defb6d5a8c32a - MD5:
1ad12bf1a940b1d07927b53013996a0b - ssdeep:
768:pgGzpDjpL5XCRrZ2ni84iz1pb2zfHPfwjaFifi5b1B+fD:KGFnpS9HQjavpB+fD - TLSH:
T1B8307CF344E7ED8C7A8BAB13ADB715552089C3896133EB605498B72CD4AC6BD7F10820 - Submitted as: zenaji.pdf
- File type: pdf · Size: 36969 bytes
- Verdict: suspicious (35/100)
Detections (2 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=oggy+and+cockroaches+game+download+apk, https://uploads.strikinglycdn.com/files/d50e27b1-dd93-4251-a8be-95c47830602b/15810733805.pdf, https://uploads.strikinglycdn.com/files/35b68986-30ba-469c-b4ff-315d44f5248b/sapigunav.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=oggy+and+cockroaches+game+download+apk
- https://uploads.strikinglycdn.com/files/d50e27b1-dd93-4251-a8be-95c47830602b/15810733805.pdf
- https://uploads.strikinglycdn.com/files/35b68986-30ba-469c-b4ff-315d44f5248b/sapigunav.pdf
- https://uploads.strikinglycdn.com/files/34d3b00f-09a1-4a46-8b37-32947c2f27dc/15599320115.pdf
- https://cdn.shopify.com/s/files/1/0485/5224/7461/files/gakijugukegilesurini.pdf
- https://cdn.shopify.com/s/files/1/0482/5713/8842/files/geometry_final_exam_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0499/2381/7640/files/nafupafuzepo.pdf
- https://cdn.shopify.com/s/files/1/0437/5665/0645/files/pokemon_omega_ruby_emulator_3ds.pdf
- https://cdn.shopify.com/s/files/1/0493/5539/1135/files/25ml_to_oz_uk.pdf
- https://uploads.strikinglycdn.com/files/cfcb214d-8ce0-47b5-86bc-9a21f14dde63/72958031766.pdf
- https://uploads.strikinglycdn.com/files/ee770f26-93b7-4de3-bd30-f31008a4048d/48155334877.pdf
- https://uploads.strikinglycdn.com/files/beed06a3-6cd0-4044-8105-2d4550399dd7/47782118219.pdf
- https://uploads.strikinglycdn.com/files/e449e0f2-ff3f-4caa-b866-fbffac960646/zaguwarox.pdf
- https://site-1039642.mozfiles.com/files/1039642/9611887225.pdf
- https://site-1036655.mozfiles.com/files/1036655/92784780647.pdf
- https://site-1039639.mozfiles.com/files/1039639/44278204927.pdf
- https://site-1043559.mozfiles.com/files/1043559/65459343271.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f876ff47e35e.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f87671852cc8.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f876b2c2ff63.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f870157b2714.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f874d0b76d56.pdf
- https://cdn.shopify.com/s/files/1/0499/3295/9912/files/65383791231.pdf
- https://cdn.shopify.com/s/files/1/0486/1054/1726/files/scaffold_user_training_ppt.pdf
- https://cdn.shopify.com/s/files/1/0495/6572/8920/files/98006748659.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1039642.mozfiles.com
- site-1036655.mozfiles.com
- site-1039639.mozfiles.com
- site-1043559.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report