SUSPICIOUS — zizasutixezibu.pdf
SUSPICIOUS — zizasutixezibu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
9b8486a79353c3e474344e76e0dc20c30c990d3b1a021030124048e04fcf629d - SHA-1:
2404520e96656c91e405d581aac26cef4143ed1b - MD5:
21736ef70055b3ad34d85bb6ee49f867 - ssdeep:
768:JgGzpDipcdrOSRh45uI7lzIdDpb8xwD/3FXYu7WZygty9EELyNe:qGF2pMWuQMdVb97OyYy9EELGe - TLSH:
T191337DF340A7DD5C7A8BAF07A9FA296C508AD7485132A764548C772DC4BC27E3F10921 - Submitted as: zizasutixezibu.pdf
- File type: pdf · Size: 48164 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=arma%203%20what%20is%20exile, https://uploads.strikinglycdn.com/files/4a765472-2721-4087-8aec-b21094f3b5a3/mukutazufunuxale.pdf, https://uploads.strikinglycdn.com/files/493379fa-02b3-4dc3-a84d-4669955af0f0/college_algebra_practice_problems.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=arma%203%20what%20is%20exile
- https://uploads.strikinglycdn.com/files/4a765472-2721-4087-8aec-b21094f3b5a3/mukutazufunuxale.pdf
- https://uploads.strikinglycdn.com/files/493379fa-02b3-4dc3-a84d-4669955af0f0/college_algebra_practice_problems.pdf
- https://uploads.strikinglycdn.com/files/499b0d29-be0e-4fa1-b63e-8cc32731b418/5533874730.pdf
- https://uploads.strikinglycdn.com/files/5689fe8e-1f4f-4e0f-abf0-ec1b22b0847a/52137062897.pdf
- https://uploads.strikinglycdn.com/files/91c512c5-7e1f-4623-b188-053f8222f938/vuxonewupigatanorita.pdf
- https://uploads.strikinglycdn.com/files/bc8d7e7a-1eda-4fd5-bea1-871d0ec45c10/rurexetos.pdf
- https://uploads.strikinglycdn.com/files/76f2dab2-0123-48a6-80e4-907d30377ee6/mozonutekukozewovana.pdf
- https://uploads.strikinglycdn.com/files/0f9dad88-4890-4068-884f-4e6d475b093b/15736275480.pdf
- https://uploads.strikinglycdn.com/files/a700139c-602f-4dcd-94c7-1a39d8b46972/45116030185.pdf
- https://uploads.strikinglycdn.com/files/4b6e5ccd-6a69-4f1e-b33d-607f08362ac3/woxoz.pdf
- https://cdn-cms.f-static.net/uploads/4365649/normal_5f87f2b9a62f7.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f871ad8bebd1.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f872ea97a3af.pdf
- https://cdn-cms.f-static.net/uploads/4371025/normal_5f8b2403af4ed.pdf
- https://mapipuluzobeb.weebly.com/uploads/1/3/1/3/131398440/0510e770fb99.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/1190097.pdf
- https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/kuzuzekajipalazam.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/7059380717.pdf
- https://cdn.shopify.com/s/files/1/0484/7645/5066/files/john_oliver_season_6_episode_2.pdf
- https://nitiruminaxodax.weebly.com/uploads/1/3/0/7/130738633/nizikup_pedijekes_warozibeb.pdf
- https://zalopajozi.weebly.com/uploads/1/3/1/4/131453352/fejesugotu.pdf
- https://mizunawakore.weebly.com/uploads/1/3/1/4/131406356/8701538.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- mapipuluzobeb.weebly.com
- vodipewelo.weebly.com
- tekegalesi.weebly.com
- cdn.shopify.com
- nitiruminaxodax.weebly.com
- zalopajozi.weebly.com
- mizunawakore.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report