SUSPICIOUS — zozufukonogemaz.pdf
SUSPICIOUS — zozufukonogemaz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
596e30cc3475cb9bc97590c931b72aa1b512ed4d28ffdf341333af3d9cf774f7 - SHA-1:
9415798df0f6967ecb8a44ecdef1979f3d26b4eb - MD5:
f054d48bf7d98c0e52f59183b8b53b13 - ssdeep:
768:mgGzpDwadmsrmAFs+DZlFHfqWxjLilUDz7mnARhOQfRPK2Yiz+:zGF8aLm+s+DZmiDz7txKRiz+ - TLSH:
T10232AFF34067ED8D768BAB036DE71069A186D68C7126AA5014947B3DC47C6FDBE00A11 - Submitted as: zozufukonogemaz.pdf
- File type: pdf · Size: 45775 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=chest+workout+program+pdf, https://uploads.strikinglycdn.com/files/31bf4a02-0d21-4989-b2d5-487f2cc371cc/5685785214.pdf, https://uploads.strikinglycdn.com/files/af86103f-22cf-45fb-910c-8fee69c6bc9f/sififejibakelozuveb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=chest+workout+program+pdf
- https://uploads.strikinglycdn.com/files/31bf4a02-0d21-4989-b2d5-487f2cc371cc/5685785214.pdf
- https://uploads.strikinglycdn.com/files/af86103f-22cf-45fb-910c-8fee69c6bc9f/sififejibakelozuveb.pdf
- https://uploads.strikinglycdn.com/files/f1531c14-d8ef-4041-b581-fa00b9890853/47954667942.pdf
- https://cdn.shopify.com/s/files/1/0429/9181/2767/files/45941993446.pdf
- https://cdn.shopify.com/s/files/1/0437/6503/9261/files/mogefumew.pdf
- https://cdn.shopify.com/s/files/1/0437/2027/8171/files/79444721517.pdf
- https://site-1036871.mozfiles.com/files/1036871/puzabobinebaxewomenerako.pdf
- https://site-1036724.mozfiles.com/files/1036724/44785810581.pdf
- https://site-1037279.mozfiles.com/files/1037279/80925406785.pdf
- https://site-1036702.mozfiles.com/files/1036702/wobiraxukakusavu.pdf
- https://site-1036951.mozfiles.com/files/1036951/92155158173.pdf
- https://cdn.shopify.com/s/files/1/0459/9309/9421/files/federal_reserve_act_apush.pdf
- https://cdn.shopify.com/s/files/1/0431/2937/2832/files/pavujipege.pdf
- https://cdn.shopify.com/s/files/1/0432/8305/4757/files/zakozegapowasufa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1036871.mozfiles.com
- site-1036724.mozfiles.com
- site-1037279.mozfiles.com
- site-1036702.mozfiles.com
- site-1036951.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report