SUSPICIOUS — zosotanuvuz.pdf
SUSPICIOUS — zosotanuvuz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2917afc8e53359b05b632492f99652c53f6243d86bf65673c39e40fb6bbd0f1c - SHA-1:
b671d4f14de0c2133fe94fab263768d6755e9259 - MD5:
585e04bd0d399093c81766c32a90cb57 - ssdeep:
768:2gGzpD3px1FStohP+3Xic0nEo9TAd85+6F1bwbVfxEUnEeu6QM:jGFbpxm0p9Udu1bOVfbEeu6QM - TLSH:
T15D306CF350D7ED8C7A8E6B03AEEB1059918BD78C613AD260048C766DD07C6ED7E10A25 - Submitted as: zosotanuvuz.pdf
- File type: pdf · Size: 38605 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=yamaha%20bear%20tracker%20owners%20manual, https://uploads.strikinglycdn.com/files/42f5974d-e87a-419c-96e0-03800051bf8f/taziloritujozopedojigidi.pdf, https://uploads.strikinglycdn.com/files/50e0a144-9ca0-41c5-bf7c-fa105d77f27f/50459957308.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=yamaha%20bear%20tracker%20owners%20manual
- https://uploads.strikinglycdn.com/files/42f5974d-e87a-419c-96e0-03800051bf8f/taziloritujozopedojigidi.pdf
- https://uploads.strikinglycdn.com/files/50e0a144-9ca0-41c5-bf7c-fa105d77f27f/50459957308.pdf
- https://uploads.strikinglycdn.com/files/87587c65-b239-41f9-8751-ab8f3c057b72/41071367363.pdf
- https://uploads.strikinglycdn.com/files/d06dc450-55ba-44bd-bf87-eab1c800d243/39006160687.pdf
- https://uploads.strikinglycdn.com/files/ec3fa677-3791-4e8f-a26f-34e8748630fa/20611934530.pdf
- https://uploads.strikinglycdn.com/files/71496c82-7d02-421c-9119-d3f5c86d61b7/59030255602.pdf
- https://uploads.strikinglycdn.com/files/f741f694-0c36-4310-b411-8b18824ada7e/dbs_kefla_porn.pdf
- https://uploads.strikinglycdn.com/files/1e8d41c9-a165-418c-a8ec-51944d48edd2/40734212989.pdf
- https://cdn.shopify.com/s/files/1/0482/6637/9425/files/85887717360.pdf
- https://cdn.shopify.com/s/files/1/0268/8683/2302/files/22319487163.pdf
- https://cdn.shopify.com/s/files/1/0494/5071/3255/files/damufofiboxe.pdf
- https://cdn.shopify.com/s/files/1/0433/7988/4186/files/define_population_distribution_in_biology.pdf
- https://uploads.strikinglycdn.com/files/367c195a-0000-42d0-8b33-2d313df18302/69948242811.pdf
- https://uploads.strikinglycdn.com/files/c9c94d0e-6857-48dd-9308-d4d5a3bf3716/zewovesawofomefalo.pdf
- https://uploads.strikinglycdn.com/files/529a6109-33c3-49ae-ac22-10d0dd9b861c/zefeduruxepivotajemevet.pdf
- https://cdn.shopify.com/s/files/1/0485/0565/1355/files/9957516923.pdf
- https://cdn.shopify.com/s/files/1/0496/0685/2757/files/jupukugiluvizudozujizid.pdf
- https://cdn.shopify.com/s/files/1/0484/1701/3912/files/motorola_arris_surfboard_sb6121_manual.pdf
- https://cdn.shopify.com/s/files/1/0436/3000/2336/files/estudio_biblico_don_de_profecia.pdf
- https://uploads.strikinglycdn.com/files/799c240e-9ea9-4d8b-af2c-4293d0eedcf4/fawegoxoraxotebepazenemu.pdf
- https://uploads.strikinglycdn.com/files/91fa5188-8c17-4627-b873-f6f1ee08e4d8/65230151280.pdf
- https://uploads.strikinglycdn.com/files/f9ef22d2-9d9f-4691-805c-2053acf67ded/kuvajubagu.pdf
- https://uploads.strikinglycdn.com/files/68a6c9b5-6bf5-4b47-b342-a1d60ace84fe/6548300458.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report