SUSPICIOUS — zixotipu.pdf
SUSPICIOUS — zixotipu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9908d589692fd28491d29f291ea45097f7260775b0fe3d54de4ab0359ccb3168 - SHA-1:
eb3a20e640040fefed3788b8874ab8ad69921e52 - MD5:
047747b66ec7158d8045ad98755b5fe1 - ssdeep:
768:acgGzpDwpFeu4dVWWbjTDwI0WDVvEh0TABdQZ2ogf8BQuOOTVZo/0LSb91tGQn2:SGFsphWnfwAJsYIpf8BRTVM02brtH2 - TLSH:
T1E8328DF35097DD4CBB8B9F035DAB11A9504AC38DA272976085887B2CC4BC9FDBE51821 - Submitted as: zixotipu.pdf
- File type: pdf · Size: 45424 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=tortora%20microbiology%2013th%20edition, https://cdn-cms.f-static.net/uploads/4370071/normal_5f8822a128f72.pdf, https://cdn-cms.f-static.net/uploads/4366366/normal_5f884579c4338.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=tortora%20microbiology%2013th%20edition
- https://cdn-cms.f-static.net/uploads/4370071/normal_5f8822a128f72.pdf
- https://cdn-cms.f-static.net/uploads/4366366/normal_5f884579c4338.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f88bdf2aaeba.pdf
- https://site-1039219.mozfiles.com/files/1039219/pelivusefojil.pdf
- https://site-1045312.mozfiles.com/files/1045312/sodemamorowof.pdf
- https://site-1038897.mozfiles.com/files/1038897/79890915951.pdf
- https://site-1038737.mozfiles.com/files/1038737/tuzinenib.pdf
- https://site-1040006.mozfiles.com/files/1040006/17881823408.pdf
- https://site-1043939.mozfiles.com/files/1043939/sitevewewugowejokozet.pdf
- https://uploads.strikinglycdn.com/files/e251365d-60e0-4bf1-8bec-f9e30e29dd85/17895059195.pdf
- https://uploads.strikinglycdn.com/files/300b670a-23ca-4a86-b85b-ef18fa216b56/99437139873.pdf
- https://uploads.strikinglycdn.com/files/641827d1-771f-4b72-a5ee-dc49574f9671/28002490869.pdf
- https://uploads.strikinglycdn.com/files/c53ab014-5b2e-4b22-ba69-7e28c217fe04/24288867834.pdf
- https://site-1043406.mozfiles.com/files/1043406/lanojixej.pdf
- https://site-1039405.mozfiles.com/files/1039405/52114684456.pdf
- https://site-1041768.mozfiles.com/files/1041768/95450459082.pdf
- https://molisemopum.weebly.com/uploads/1/3/1/4/131437834/jefujowidegupe.pdf
- https://legadiduzavof.weebly.com/uploads/1/3/2/6/132681829/larumasex-japexexofuwed-pepuleb.pdf
- https://kizekusoviwo.weebly.com/uploads/1/3/1/4/131453028/mokerelakizebubu.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/mabexa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1039219.mozfiles.com
- site-1045312.mozfiles.com
- site-1038897.mozfiles.com
- site-1038737.mozfiles.com
- site-1040006.mozfiles.com
- site-1043939.mozfiles.com
- uploads.strikinglycdn.com
- site-1043406.mozfiles.com
- site-1039405.mozfiles.com
- site-1041768.mozfiles.com
- molisemopum.weebly.com
- legadiduzavof.weebly.com
- kizekusoviwo.weebly.com
- megadezatesaram.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report