SUSPICIOUS — zuzokarasig.pdf
SUSPICIOUS — zuzokarasig.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
5c4399981588515a83d639124a673a5be208e9fd9031dd1060fd0e979c8de81f - SHA-1:
c604c6661b7ff675c61ad9f11c8f6521b4fa5e28 - MD5:
1894d0c50af7361e1db7ba94b39a333f - ssdeep:
768:fgGzpDzpREM9pJsxDMHYYUdsyBNcjimSRKbUje6VsFjW5M8fY6owo90QDDdH5xM:oGFfpkEimUzZ5My2RtH5xM - TLSH:
T12B326BF311A7EC4C7ACBAF03AAEA296D5189D64C6023A765548C262DC4BC77D7F00960 - Submitted as: zuzokarasig.pdf
- File type: pdf · Size: 44533 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=fallout%204%20valdacil%20item%20sorting, https://site-1043763.mozfiles.com/files/1043763/zuzojakitovododemebegonu.pdf, https://site-1036713.mozfiles.com/files/1036713/47382523066.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=fallout%204%20valdacil%20item%20sorting
- https://site-1043763.mozfiles.com/files/1043763/zuzojakitovododemebegonu.pdf
- https://site-1036713.mozfiles.com/files/1036713/47382523066.pdf
- https://site-1043414.mozfiles.com/files/1043414/best_android_tv_box_egypt.pdf
- https://site-1042922.mozfiles.com/files/1042922/tkinter_python_3_book.pdf
- https://site-1037867.mozfiles.com/files/1037867/nurasuzirorakosoka.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f86fd81d5f4e.pdf
- https://cdn-cms.f-static.net/uploads/4368984/normal_5f88425c892d5.pdf
- https://cdn-cms.f-static.net/uploads/4368222/normal_5f877be9d41b4.pdf
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f874610c5a0a.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f883ca238972.pdf
- https://uploads.strikinglycdn.com/files/6d34657b-73ab-46a4-aa04-b2c84bb4e527/99933057729.pdf
- https://uploads.strikinglycdn.com/files/2b121552-41be-4dfd-a5b7-c980b803bc4c/jidiw.pdf
- https://uploads.strikinglycdn.com/files/4bc40ea2-9104-4440-843a-848ebd06f47d/fivevaludevemesajuvojisos.pdf
- https://uploads.strikinglycdn.com/files/c12f666a-6f10-452a-ba87-4d4e834f69c0/32018433904.pdf
- https://cdn.shopify.com/s/files/1/0482/6637/9425/files/65501405549.pdf
- https://cdn.shopify.com/s/files/1/0496/5901/9421/files/call_tires_plus_eagan_minnesota.pdf
- https://cdn.shopify.com/s/files/1/0496/1527/4147/files/unidad_2_leccion_1_gramatica_a_answers.pdf
- https://cdn.shopify.com/s/files/1/0435/3972/6487/files/rabopijigifolu.pdf
- https://cdn.shopify.com/s/files/1/0493/6119/1071/files/mijifanobino.pdf
- https://cdn.shopify.com/s/files/1/0266/8878/2517/files/west_virginia_state_flower_images.pdf
- https://uploads.strikinglycdn.com/files/058be158-182d-4a79-ab19-8dbabc855be4/baguvosewebibapojobegaleg.pdf
- https://uploads.strikinglycdn.com/files/2a188c4c-ee70-4cbc-a33d-a0ded603f229/27947740450.pdf
- https://uploads.strikinglycdn.com/files/18d151eb-faf4-4fe5-9b73-7c843e09b23b/76218237293.pdf
- https://uploads.strikinglycdn.com/files/7f3efa70-f85f-4e8b-beda-68305bed306f/58414045861.pdf
Embedded domains
- gettraff.ru
- site-1043763.mozfiles.com
- site-1036713.mozfiles.com
- site-1043414.mozfiles.com
- site-1042922.mozfiles.com
- site-1037867.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report