SUSPICIOUS — zimojonax.pdf
SUSPICIOUS — zimojonax.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4f0431e38f726b94293e75c66eb02b73a9c7ac49aa4fefaa04ba6eeaf7abbe3d - SHA-1:
3aee9ca56aa781353ad60bed606eaeefbb37e5af - MD5:
f4e19e75e59aae6bfb96b882aedf776b - ssdeep:
768:2gGzpDqpTcklvT3WLhWuVeasxrNvn+o+OpKUqaMdUqer0YmVck3gXrMfKYEBJL6l:jGF+pIZVeaMrNf+epv3MPXc3MrEBJL6l - TLSH:
T19D338DF31067ED4D7A8BAFA3AEAE1158604A92847133976014C8373DD47C7EE6F40562 - Submitted as: zimojonax.pdf
- File type: pdf · Size: 49103 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=gta%20san%20andreas%20onecoin, https://cdn.shopify.com/s/files/1/0266/8583/3416/files/bissell_spotclean_proheat_manual.pdf, https://cdn.shopify.com/s/files/1/0496/5043/4211/files/video_maker_terbaik_android.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=gta%20san%20andreas%20onecoin
- https://s3.amazonaws.com/subud/sonubeguromigarilifekuja.pdf
- https://s3.amazonaws.com/gupuso/345563459.pdf
- https://s3.amazonaws.com/mijedusovineti/digelupaxewo.pdf
- https://s3.amazonaws.com/wonoti/63144760210.pdf
- https://cdn.shopify.com/s/files/1/0266/8583/3416/files/bissell_spotclean_proheat_manual.pdf
- https://cdn.shopify.com/s/files/1/0496/5043/4211/files/video_maker_terbaik_android.pdf
- https://cdn.shopify.com/s/files/1/0503/8650/1806/files/32996814613.pdf
- https://cdn.shopify.com/s/files/1/0431/3071/6314/files/vulgarisation_agricole_au_burkina_faso.pdf
- https://uploads.strikinglycdn.com/files/047afcc3-776b-403e-bb93-86e2919596e5/73720639406.pdf
- https://uploads.strikinglycdn.com/files/31c7e62e-a9e4-4428-9fd5-9eac96d50075/laluwiputofesuwi.pdf
- https://uploads.strikinglycdn.com/files/14ad6c97-668b-4f06-95aa-78866f370c1f/bawolemawun.pdf
- https://uploads.strikinglycdn.com/files/ac4b282c-10e3-444d-a456-1020e6ef7750/36519044251.pdf
- https://uploads.strikinglycdn.com/files/8e0f905c-8818-47c5-b897-f4a00c316054/20054551038.pdf
- https://uploads.strikinglycdn.com/files/12f0b734-0739-4abb-8156-888a688da352/97580773548.pdf
- https://uploads.strikinglycdn.com/files/1c31ae2d-3e6d-4178-8953-b5a157b98517/fanemivajes.pdf
- https://uploads.strikinglycdn.com/files/9df44293-6010-4937-8111-b7dc28e19292/breath_of_the_wild_vah_ruta_guide.pdf
- https://uploads.strikinglycdn.com/files/34fef426-782e-451f-8fbf-05fb5999976c/kumujenefarexodafogajasil.pdf
- https://uploads.strikinglycdn.com/files/ddef6453-970f-43f5-84bc-075a0f7548dd/9514637272.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report