SUSPICIOUS — zixomagasi.pdf
SUSPICIOUS — zixomagasi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ed401dd82f74fd7b3e32e33efbd3be73854d649c09a0552830391b4e6a8d53ab - SHA-1:
5fee726bf3a26795d6b86d4d280a57a93511d2d2 - MD5:
061df816df16991c802c53e3cd8f83a7 - ssdeep:
768:ebgGzpDYdrrghLmcK6NJXCUUGFT9OWnPapmoERiCfQ6s2KGK8aQ+k1BLsB7pYWTa:9GFElEvNFEE1fQP4Za/c5WTkXhvk5i - TLSH:
T12B33AFF30093DD8D7A8B6F93ADE71099A14A97C97162D3A044CC6B6CC57C6BCAF40960 - Submitted as: zixomagasi.pdf
- File type: pdf · Size: 50852 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=mecanica+dos+materiais+7+edi%25C3%25A7%25C3%25A3o+pdf, https://cdn.shopify.com/s/files/1/0429/5308/0985/files/93887457613.pdf, https://cdn.shopify.com/s/files/1/0496/7700/9060/files/scp_529_j.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=mecanica+dos+materiais+7+edi%25C3%25A7%25C3%25A3o+pdf
- https://cdn.shopify.com/s/files/1/0429/5308/0985/files/93887457613.pdf
- https://cdn.shopify.com/s/files/1/0496/7700/9060/files/scp_529_j.pdf
- https://cdn.shopify.com/s/files/1/0485/7734/7744/files/80854451730.pdf
- https://cdn.shopify.com/s/files/1/0437/6631/7205/files/heat_n_glo_sl-750tr-c_manual.pdf
- https://cdn.shopify.com/s/files/1/0481/2088/9506/files/guest_house_plans_modern.pdf
- http://files.jessica-yeeun-kang.com/uploads/1/3/0/7/130739298/fiwofavonuz_sixivuv.pdf
- http://files.crupropertymanagement.es/uploads/1/3/1/4/131406108/776ec0d.pdf
- https://cdn.shopify.com/s/files/1/0429/6025/7177/files/sitegimevorapoz.pdf
- https://cdn.shopify.com/s/files/1/0479/7867/6380/files/komuwunonuvapalizakeru.pdf
- https://cdn.shopify.com/s/files/1/0429/1228/4831/files/gimarim.pdf
- https://cdn.shopify.com/s/files/1/0431/8547/1656/files/esky_shock_collar_manual.pdf
- https://cdn.shopify.com/s/files/1/0429/4115/3439/files/wofum.pdf
- https://uploads.strikinglycdn.com/files/fb6022d3-1eec-4ccf-b382-1f99dab0b2cc/watoragoz.pdf
- https://uploads.strikinglycdn.com/files/b1b6400b-e5dc-47fa-a30e-f2c58ab25f5e/59691863567.pdf
- https://uploads.strikinglycdn.com/files/dcea64c1-c007-4dda-bd88-b7006033fb3a/lujenulozotapumidezu.pdf
- https://uploads.strikinglycdn.com/files/4768c107-ff60-4b51-9d70-b09b8cfdf7d8/mibosiwudedi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- files.jessica-yeeun-kang.com
- files.crupropertymanagement.es
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report