SUSPICIOUS — zipozixunewakipab.pdf
SUSPICIOUS — zipozixunewakipab.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
a0ec562aa23fccf72b5f65b5e07806460c7fb1c2aad879d3e39000bcc96931ee - SHA-1:
198a35c833dc9f12006a1b38f73eeeef1b643636 - MD5:
0074390c036ea0efc69790ade6e2311b - ssdeep:
1536:BGFfeOfKEF/FtibEhoSh6H7KviWj8GvkBg:kFfeOSEdib2h6H72h8Gv3 - TLSH:
T1B1359FF34057DD8C7B9AEB03A9EB0058618ACBC83136AAA0449C7B6DC47C9FD6D50E51 - Submitted as: zipozixunewakipab.pdf
- File type: pdf · Size: 59620 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=hyperion+launcher+mod+apk, https://uploads.strikinglycdn.com/files/2c25782f-94be-4168-afe3-c2fe6c7940ab/filigifivodapiwajetixiro.pdf, https://uploads.strikinglycdn.com/files/3b5efc30-5a0a-49c7-9b8e-cfe1fca087b7/33480084374.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=hyperion+launcher+mod+apk
- https://uploads.strikinglycdn.com/files/2c25782f-94be-4168-afe3-c2fe6c7940ab/filigifivodapiwajetixiro.pdf
- https://uploads.strikinglycdn.com/files/3b5efc30-5a0a-49c7-9b8e-cfe1fca087b7/33480084374.pdf
- https://uploads.strikinglycdn.com/files/32a04892-d7d3-40fa-b1af-a24bb36a65ec/81765423125.pdf
- https://uploads.strikinglycdn.com/files/3f7bbfb7-09d0-42eb-b06b-33afd616d610/famipopofesufakero.pdf
- https://site-1042102.mozfiles.com/files/1042102/7929436538.pdf
- https://site-1038880.mozfiles.com/files/1038880/76443472326.pdf
- https://site-1036698.mozfiles.com/files/1036698/56740899739.pdf
- https://site-1038326.mozfiles.com/files/1038326/fanilanozukuruxuduboneniw.pdf
- https://site-1043377.mozfiles.com/files/1043377/vajirufoxipisunipesowur.pdf
- https://site-1039861.mozfiles.com/files/1039861/jirojifidumifob.pdf
- https://site-1038702.mozfiles.com/files/1038702/74867871208.pdf
- https://site-1037203.mozfiles.com/files/1037203/tipufage.pdf
- https://site-1037129.mozfiles.com/files/1037129/sozuzigapevasomofaregetek.pdf
- https://cdn.shopify.com/s/files/1/0500/0449/2438/files/quadratic_sequences_worksheets.pdf
- https://cdn.shopify.com/s/files/1/0486/2112/5792/files/22897976860.pdf
- https://cdn.shopify.com/s/files/1/0497/5116/3043/files/hinder_all_american_nightmare_album.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1042102.mozfiles.com
- site-1038880.mozfiles.com
- site-1036698.mozfiles.com
- site-1038326.mozfiles.com
- site-1043377.mozfiles.com
- site-1039861.mozfiles.com
- site-1038702.mozfiles.com
- site-1037203.mozfiles.com
- site-1037129.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report