SUSPICIOUS — zozizawod.pdf
SUSPICIOUS — zozizawod.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
b16bdcad6dc14d62af49b274e66644ac3cd1f34ad5569b3ad02e7d6d7bb2fe55 - SHA-1:
ecee99bf86a01c482779398591b030c21527afb7 - MD5:
69f8a13fba635f000de077904a39e236 - ssdeep:
768:agGzpDUpz6TZtK+dsDfOUHaHZd7Y7Tf0V2TR6Bx5V5nDXlpoOXX/d:HGFgpzTOZd7Y7Tf08Tgv5jnDVlXX/d - TLSH:
T196317DF750A3DD9D7A879F07EDA70165258AD388B133DB604588BB2DC8BC5BD6E00860 - Submitted as: zozizawod.pdf
- File type: pdf · Size: 42537 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=converting%20customary%20units%20worksheet%206th%20grade, https://cdn-cms.f-static.net/uploads/4368984/normal_5f89460382619.pdf, https://cdn-cms.f-static.net/uploads/4371013/normal_5f88e5d1537f1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=converting%20customary%20units%20worksheet%206th%20grade
- https://cdn-cms.f-static.net/uploads/4368984/normal_5f89460382619.pdf
- https://cdn-cms.f-static.net/uploads/4371013/normal_5f88e5d1537f1.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f8a1d8e4c2da.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f8a1c0ae2939.pdf
- https://cdn-cms.f-static.net/uploads/4373264/normal_5f8a0dd55c9ab.pdf
- https://pofemazavuson.weebly.com/uploads/1/3/2/3/132303373/3762798.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/3953434.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/6594323.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/9f751f306.pdf
- https://uploads.strikinglycdn.com/files/6f1d1298-1c91-478a-8cea-2a35a56fcb98/berserk_movie_3_english_dub_online.pdf
- https://uploads.strikinglycdn.com/files/1e1e7c32-d767-4360-9637-9db962200a0f/naweximopamaruroranuf.pdf
- https://uploads.strikinglycdn.com/files/3ba590a3-8b62-4edb-8a43-e9d4f04580df/82347979602.pdf
- https://uploads.strikinglycdn.com/files/1e19cf4b-39b1-4373-95d0-3449f05b1b6f/97397413703.pdf
- https://uploads.strikinglycdn.com/files/6e26b0a8-e8ed-4ed7-ba89-d4bf5445ee6c/zuzegosobolanoxu.pdf
- https://uploads.strikinglycdn.com/files/515b5ed5-4294-4f5b-95d7-ccafbd3a3949/ravuzomuregejaxisuvujigo.pdf
- https://cdn.shopify.com/s/files/1/0496/0711/4919/files/9880077270.pdf
- https://cdn.shopify.com/s/files/1/0430/5934/7618/files/gta_vice_city_cheat_game_for_android.pdf
- https://cdn.shopify.com/s/files/1/0482/3852/6616/files/nugunipilewitatupepup.pdf
- https://uploads.strikinglycdn.com/files/0c1ebe54-2bb0-4a95-9c18-22e946bee531/kodid.pdf
- https://uploads.strikinglycdn.com/files/198becaa-d4d3-483e-866a-b86261317f9e/dapaves.pdf
- https://uploads.strikinglycdn.com/files/2209a293-9acf-4398-94be-40176c89f26f/neo_geo_aes_full_rom_set.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- pofemazavuson.weebly.com
- jezaxegare.weebly.com
- zoveponezewuda.weebly.com
- babikovinemixe.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report