SUSPICIOUS — zifowe.pdf
SUSPICIOUS — zifowe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 53 detection engines flagged it.
Identification
- SHA-256:
8cb8985a23fc61499dd4fe374fd05a302861470001ab06755b5bd76b048edb33 - SHA-1:
cf3bd1312b453814c92f11c8e47f32dbe8761d5c - MD5:
8bc0d73faf489fe48a260dcaa10e4f03 - ssdeep:
768:RgGzpDHp9KnqjbKuwZhN2+RTRx3FCrwWaYVHadPJgFVjG5C/RHZWNsJu:iGFLpt5aYZadPAGwlEN2u - TLSH:
T137306CF720D7EC8CBA869B03ADAB256A5489D748A236DB50458C772CD4BC77E7F00810 - Submitted as: zifowe.pdf
- File type: pdf · Size: 35758 bytes
- Verdict: suspicious (35/100)
Detections (1 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=1.5%20cm%20grid%20paper%20pdf, https://cdn-cms.f-static.net/uploads/4371812/normal_5f966b58986c7.pdf, https://cdn-cms.f-static.net/uploads/4368486/normal_5f894a2c7dd0a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=1.5%20cm%20grid%20paper%20pdf
- https://cdn-cms.f-static.net/uploads/4371812/normal_5f966b58986c7.pdf
- https://cdn-cms.f-static.net/uploads/4368486/normal_5f894a2c7dd0a.pdf
- https://cdn-cms.f-static.net/uploads/4368475/normal_5f88737b4d254.pdf
- https://cdn-cms.f-static.net/uploads/4390641/normal_5f9190c60ef37.pdf
- https://cdn-cms.f-static.net/uploads/4369664/normal_5f95d25447ef3.pdf
- https://uploads.strikinglycdn.com/files/e88f8460-2b17-4964-a98e-75ae91f33c0b/nifobe.pdf
- https://cdn.shopify.com/s/files/1/0483/8264/0285/files/flans_mod_minecraft_1.15.2.pdf
- https://cdn.shopify.com/s/files/1/0481/0073/7187/files/tommee_tippee_weaning_sippy_cup_instructions.pdf
- https://cdn.shopify.com/s/files/1/0433/4200/4375/files/hacker_apk_game.pdf
- https://cdn.shopify.com/s/files/1/0431/7125/0333/files/watuzugobimanovireri.pdf
- https://cdn.shopify.com/s/files/1/0432/5795/4467/files/86422022353.pdf
- https://cdn.shopify.com/s/files/1/0496/9329/4749/files/princess_connect_re_dive_apk_ios.pdf
- https://cdn.shopify.com/s/files/1/0431/8950/2111/files/68116599364.pdf
- https://cdn.shopify.com/s/files/1/0440/5588/8022/files/55554262995.pdf
- https://cdn.shopify.com/s/files/1/0498/3577/0018/files/zokitemuveb.pdf
- https://cdn.shopify.com/s/files/1/0501/5289/8739/files/kasanokiminutori.pdf
- https://godadonalizubo.weebly.com/uploads/1/3/1/4/131437317/8566273.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/lafelixopipama.pdf
- https://kafasomawupi.weebly.com/uploads/1/3/0/7/130775431/56068f049.pdf
- https://tiposowa.weebly.com/uploads/1/3/1/1/131164246/rutorujikifedez.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/dilipisomidu.pdf
- https://fulipevaxavu.weebly.com/uploads/1/3/2/6/132695351/9997097.pdf
- https://labajilawuja.weebly.com/uploads/1/3/1/4/131406369/ritip.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/9279448.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- godadonalizubo.weebly.com
- wetuxabo.weebly.com
- kafasomawupi.weebly.com
- tiposowa.weebly.com
- jakedekokobara.weebly.com
- fulipevaxavu.weebly.com
- labajilawuja.weebly.com
- papunagaku.weebly.com
- naxedomabaxa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report