SUSPICIOUS — zadabanab.pdf
SUSPICIOUS — zadabanab.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d89d3f5e35d3f648e3df7f3ead008a5b58d198dee7c709b93518c99b2f2f4c0e - SHA-1:
27333399250e4bbd5a86f11682c77f4a74a7c4b9 - MD5:
e4e0026c16f86e9c1ebafec1d7b1900c - ssdeep:
768:rgGzpDSeCk2gmrrIRpC/1FQg6Mt2Yz/sD+xqyKWy83uypNVT4odjh:UGFWeCB0gzHDGPvG3uoNuqjh - TLSH:
T171316BF300A7DD8C7ACBAB93ADA711A9A48AC78871329790048C776DD4BC5BD7F10950 - Submitted as: zadabanab.pdf
- File type: pdf · Size: 41405 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=al%20otro%20lado%20del%20muro%20capitulos%20comp, https://site-1039129.mozfiles.com/files/1039129/18181350310.pdf, https://site-1038553.mozfiles.com/files/1038553/nimanizozafotazunewuneri.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=al%20otro%20lado%20del%20muro%20capitulos%20comp
- https://site-1039129.mozfiles.com/files/1039129/18181350310.pdf
- https://site-1038553.mozfiles.com/files/1038553/nimanizozafotazunewuneri.pdf
- https://site-1037026.mozfiles.com/files/1037026/48012708874.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f88c84f6a896.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f87023283f79.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f8904c3515fc.pdf
- https://cdn-cms.f-static.net/uploads/4366969/normal_5f873728409c8.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f875ea7e42ff.pdf
- https://uploads.strikinglycdn.com/files/51764ffc-4d8e-4aee-a086-ec53494933c6/vufunakuribomopiluruw.pdf
- https://uploads.strikinglycdn.com/files/2d269e2c-faa4-43fd-b803-edb3491ce991/84959467945.pdf
- https://uploads.strikinglycdn.com/files/b35b2d81-5562-4a87-bb83-54a3c82b5d22/45586636603.pdf
- https://uploads.strikinglycdn.com/files/98327341-0178-48a2-9cfd-46d7fba91623/neditonuturafi.pdf
- https://uploads.strikinglycdn.com/files/983555e0-e390-4444-9879-7801a0778386/gunemuker.pdf
- https://uploads.strikinglycdn.com/files/d4d8fa69-626b-4312-af0e-14d46a4fb614/bitumovakovisube.pdf
- https://cdn.shopify.com/s/files/1/0496/6206/6852/files/lg_sh2_2.1_sound_bar_instructions.pdf
- https://cdn.shopify.com/s/files/1/0435/9087/7339/files/10991914478.pdf
- https://cdn.shopify.com/s/files/1/0433/2548/9305/files/51492782428.pdf
- https://cdn.shopify.com/s/files/1/0490/0805/0343/files/swtor_endgame_gearing_guide.pdf
- https://uploads.strikinglycdn.com/files/006d1c9a-98b3-4a7e-8625-47f31091b1dc/40944769485.pdf
- https://uploads.strikinglycdn.com/files/2bfadc20-061c-4b79-a5f8-9be9b8c3015b/komoroduj.pdf
- https://uploads.strikinglycdn.com/files/217feb0d-4e02-4caf-a641-b2f2171f55f0/91420150225.pdf
- https://uploads.strikinglycdn.com/files/0edea4c4-e45a-409e-b80f-a864e0670389/69913476097.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- site-1039129.mozfiles.com
- site-1038553.mozfiles.com
- site-1037026.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report