SUSPICIOUS — zakonajog.pdf
SUSPICIOUS — zakonajog.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100), attributed to the STRATO family. 3 of 50 detection engines flagged it.
Identification
- SHA-256:
618e1fb2b754912ea510dffb83792df2ed92d6fb0d7d49cf4b9a74a2802b9c71 - SHA-1:
33a09d04a7e0a098e3307bc1891fc2cdd0f145a2 - MD5:
3c42f0ea9aeea659683ff7013be9d82f - ssdeep:
768:XgGzpDjpMRD0Andt0cOb7OYV0u80P9y3B9riBPXFsYXIqYGN1M3CAlyFW5kNoMZd:wGF3pMRDay2XyYXIqNM3C8+W5kNoMZd - TLSH:
T16C34BFF351ABED4C7A86EB039DEA115AB05593C91232EB7458C87B2CC07C77D6D20A60 - Submitted as: zakonajog.pdf
- File type: pdf · Size: 53147 bytes
- Verdict: suspicious (58/100) · Family: STRATO
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://gettraff.ru/wb?keyword=samsung%20washing%20machine%20front%20loader%20manual, https://cdn.shopify.com/s/files/1/0482/0880/6045/files/to_engineer_is_human_chapter_summary.pdf, https://cdn.shopify.com/s/files/1/0428/2449/9367/files/poputugusureg.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=samsung%20washing%20machine%20front%20loader%20manual
- https://cdn.shopify.com/s/files/1/0482/0880/6045/files/to_engineer_is_human_chapter_summary.pdf
- https://cdn.shopify.com/s/files/1/0428/2449/9367/files/poputugusureg.pdf
- https://cdn.shopify.com/s/files/1/0484/8890/6902/files/nezudipovepiwur.pdf
- https://cdn.shopify.com/s/files/1/0485/7662/6848/files/ladoziwilisiwugowogerux.pdf
- https://cdn.shopify.com/s/files/1/0434/5587/3190/files/form_2553_irs.pdf
- https://cdn.shopify.com/s/files/1/0477/0119/6966/files/17836939268.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f87026796cac.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f87183d05ad4.pdf
- https://cdn.shopify.com/s/files/1/0500/4102/8761/files/41511281220.pdf
- https://cdn.shopify.com/s/files/1/0432/1270/1854/files/windows_xp_activator.exe.pdf
- https://cdn.shopify.com/s/files/1/0488/4008/1573/files/oracle_bi_publisher_12c.pdf
- https://cdn.shopify.com/s/files/1/0494/3750/7751/files/lejanijoj.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f870a1e96733.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f8707eb09c59.pdf
- https://jeponiruwapin.weebly.com/uploads/1/3/0/7/130776483/gigufoteworakef-bezari.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/ruxozukozuvazu.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/xokav.pdf
- https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/5ed733af3ee4002.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- jeponiruwapin.weebly.com
- jatorogerujew.weebly.com
- mojivimimujovo.weebly.com
- tudupumodowi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
More STRATO samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report