SUSPICIOUS — zigoxikegapud.pdf
SUSPICIOUS — zigoxikegapud.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
d604e8e78d3a3d2b3f62c6857c26d867005cd3d17f3bef92dd16fa819c686c0e - SHA-1:
ce7265b674490129a5b3b81b7123c334806c961a - MD5:
5491fbc3c93861842345f41928edb9bc - ssdeep:
768:/gGzpDkpJw2LPMerXpDC1D0WaFcUQa08+0SI3fn5DzWfw81oY6:IGFwpE+lpSGfn5vWfw81oY6 - TLSH:
T117328EF310A7ED4DBACB9F53AEA72199554EC389B03AA7A440CC762CC47C69D6F10811 - Submitted as: zigoxikegapud.pdf
- File type: pdf · Size: 46753 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=zoloto%20non%20return%20valve%20catalogue%20pdf, https://cdn-cms.f-static.net/uploads/4379485/normal_5f9156ac6268f.pdf, https://cdn-cms.f-static.net/uploads/4366324/normal_5f94fa7fd1bec.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=zoloto%20non%20return%20valve%20catalogue%20pdf
- https://cdn-cms.f-static.net/uploads/4379485/normal_5f9156ac6268f.pdf
- https://cdn-cms.f-static.net/uploads/4366324/normal_5f94fa7fd1bec.pdf
- https://cdn-cms.f-static.net/uploads/4367304/normal_5f875a213a9da.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f928bffa4872.pdf
- https://cdn-cms.f-static.net/uploads/4367294/normal_5f8bb7666bfa0.pdf
- https://cdn-cms.f-static.net/uploads/4376878/normal_5f91ca1ee418a.pdf
- https://cdn-cms.f-static.net/uploads/4384831/normal_5f8d2f923b2e4.pdf
- https://cdn-cms.f-static.net/uploads/4393180/normal_5f95cb8fe795c.pdf
- https://cdn-cms.f-static.net/uploads/4366655/normal_5f87b12180b56.pdf
- https://uploads.strikinglycdn.com/files/19655fed-9b82-4f2a-bc34-cfa215c15d49/18795626214.pdf
- https://uploads.strikinglycdn.com/files/b278dc3b-1d2e-4d87-8cb7-490b268b0ad5/20697130375.pdf
- https://uploads.strikinglycdn.com/files/f97725aa-7272-46b7-9717-7b420ad35372/41463424054.pdf
- https://uploads.strikinglycdn.com/files/d5a84144-9fc7-4412-85b2-306d2bf5cd1f/nedisonaborodus.pdf
- https://s3.amazonaws.com/leguvefu/lonely_planet_vietnam_cambodia_laos_northern_thailand_download.pdf
- https://s3.amazonaws.com/xanebavifamopez/kepulekavakuvozar.pdf
- https://s3.amazonaws.com/kigavanus/b._ed_syllabus_odisha.pdf
- https://s3.amazonaws.com/zebarufuridorur/list_of_important_days_in_telugu.pdf
- https://s3.amazonaws.com/fopalew/degradacion_del_suelo_por_agricultura.pdf
- https://bafovulik.weebly.com/uploads/1/3/1/0/131070506/lajoko.pdf
- https://zazejisodixad.weebly.com/uploads/1/3/4/3/134359446/nebelopiwave.pdf
- https://sujajikozodes.weebly.com/uploads/1/3/1/3/131384638/03069993f12a56a.pdf
- https://lowizozexide.weebly.com/uploads/1/3/0/7/130776176/3371310.pdf
- https://uploads.strikinglycdn.com/files/6e6a7977-71b8-40ce-9148-2377484b3726/wivekuziwawamo.pdf
- https://uploads.strikinglycdn.com/files/398c54b8-aee7-473d-8a9f-22b3dd11b679/desafadujuweb.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- bafovulik.weebly.com
- zazejisodixad.weebly.com
- sujajikozodes.weebly.com
- lowizozexide.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report