SUSPICIOUS — zapolasogeju.pdf
SUSPICIOUS — zapolasogeju.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7096309ecf93e8940f238ab7c87f754a5ae6ef0d533389c1691ba0f2885df179 - SHA-1:
27c031c222dc6f67ad3e583859a7140f8ae70939 - MD5:
9e0c9a960564bc6a3d79578a6f2776f7 - ssdeep:
768:C+gGzpDupoa9HHJ52LlcQOn6SO095P+Oc3X1nGv9nv28NbIF:wGFSpogJ0LSPHP+Oo1Gv9n+8NbIF - TLSH:
T16E315BF35067DD4C7A86DB03AEEA240C5489EB896172DB54849C7B2CC4BC7BE6F10960 - Submitted as: zapolasogeju.pdf
- File type: pdf · Size: 39690 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=nissan%20versa%20haynes%20repair%20manual%20pd, https://site-1039289.mozfiles.com/files/1039289/5064850641.pdf, https://site-1043541.mozfiles.com/files/1043541/79269504724.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=nissan%20versa%20haynes%20repair%20manual%20pd
- https://site-1039289.mozfiles.com/files/1039289/5064850641.pdf
- https://site-1043541.mozfiles.com/files/1043541/79269504724.pdf
- https://site-1042355.mozfiles.com/files/1042355/templates_in_c.pdf
- https://site-1039646.mozfiles.com/files/1039646/mexiwotiwabolepopabax.pdf
- https://site-1041491.mozfiles.com/files/1041491/pudupajobijujupijumenaxe.pdf
- https://site-1043086.mozfiles.com/files/1043086/darosivevufixekova.pdf
- https://site-1043297.mozfiles.com/files/1043297/baradujatojewejojej.pdf
- https://site-1039873.mozfiles.com/files/1039873/bebitizipu.pdf
- https://site-1039933.mozfiles.com/files/1039933/12486367079.pdf
- https://site-1038472.mozfiles.com/files/1038472/vaxesijirap.pdf
- https://uploads.strikinglycdn.com/files/0c0b8688-b7ec-4b28-a953-daf25cb41500/dirafefusitosopujituguxep.pdf
- https://uploads.strikinglycdn.com/files/b7a746c4-86e6-4b13-b056-a536df4f584c/jusokunitufek.pdf
- https://uploads.strikinglycdn.com/files/22c1d196-3397-4976-825c-b20956e74211/92554216920.pdf
- https://uploads.strikinglycdn.com/files/e5761455-6b1c-4a11-a488-11b2896a990c/38379864892.pdf
- https://uploads.strikinglycdn.com/files/b8420809-4d9e-42c0-8f3a-8bebab599d92/68361313402.pdf
- https://uploads.strikinglycdn.com/files/e4292ebf-ff12-4267-8900-80bfe83de923/naluwuk.pdf
- https://uploads.strikinglycdn.com/files/2ab86f7e-08d0-407a-afd3-8442c853d408/mexuwel.pdf
- https://uploads.strikinglycdn.com/files/75bbd168-b543-48c5-a301-b1d3fd152464/sifonokuwezopeme.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f874258ce743.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f87c4803f56d.pdf
- http://diyservicemanuals.com/nissan-versa-service-repair-manuals/Alle
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- site-1039289.mozfiles.com
- site-1043541.mozfiles.com
- site-1042355.mozfiles.com
- site-1039646.mozfiles.com
- site-1041491.mozfiles.com
- site-1043086.mozfiles.com
- site-1043297.mozfiles.com
- site-1039873.mozfiles.com
- site-1039933.mozfiles.com
- site-1038472.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- diyservicemanuals.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report