SUSPICIOUS — lazeb.pdf
SUSPICIOUS — lazeb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
21e2a85010a97a333c91d9cd94d03862cb5712676b12f68cb9c13135f5a9273e - SHA-1:
00b56afc6556f1062c48df69f369a9086a4f6226 - MD5:
4218d9d2d3d3f7225ad87e49102b560d - ssdeep:
768:agGzpDHYpKeOg+xNtPPzfQM5yM4rcTrMh65zx7GjibFRffhqcbwguxUzTkK:HGFUpKhdTrME50ihRRzwDGzTkK - TLSH:
T1D8327CF300A7ED4E7A87AF0379AB21699059D38CA032E75055AC366CC47C7BE7E10961 - Submitted as: lazeb.pdf
- File type: pdf · Size: 45256 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=the%20everly%20brothers%20let%20it%20be%20me, https://site-1038555.mozfiles.com/files/1038555/64817986742.pdf, https://site-1038790.mozfiles.com/files/1038790/13733448275.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=the%20everly%20brothers%20let%20it%20be%20me
- https://site-1038555.mozfiles.com/files/1038555/64817986742.pdf
- https://site-1038790.mozfiles.com/files/1038790/13733448275.pdf
- https://site-1040376.mozfiles.com/files/1040376/33832651056.pdf
- https://site-1043176.mozfiles.com/files/1043176/88102297753.pdf
- https://uploads.strikinglycdn.com/files/d871c6ac-2e93-49c2-b6ad-ddf42edddaa7/pevaguxosavip.pdf
- https://uploads.strikinglycdn.com/files/01481792-d4e5-4d87-975a-87a73ded9db4/fizexerewu.pdf
- https://uploads.strikinglycdn.com/files/df4d49c5-7889-4e89-b862-838242ba4bd7/dufepaxavubabore.pdf
- https://uploads.strikinglycdn.com/files/4a93d4f3-c1a2-4e90-91c1-13d87712f8e9/jipuwipufeniride.pdf
- https://uploads.strikinglycdn.com/files/ce36a293-fdb2-4dbd-ba08-d2997ab40bdf/rotewegel.pdf
- https://cdn.shopify.com/s/files/1/0266/8671/8129/files/53355443672.pdf
- https://cdn.shopify.com/s/files/1/0499/2463/6823/files/ahima_cca_exam_study_guide.pdf
- https://cdn.shopify.com/s/files/1/0499/8597/8518/files/jeguf.pdf
- https://cdn.shopify.com/s/files/1/0433/9721/8471/files/tottenham_fixtures_2020_19.pdf
- https://cdn.shopify.com/s/files/1/0495/4891/8951/files/76214477248.pdf
- https://cdn.shopify.com/s/files/1/0488/5581/0204/files/one_proportion_z_test_p_value_calculator.pdf
- https://cdn.shopify.com/s/files/1/0488/2871/1077/files/rakofalivunamuwonusefidiz.pdf
- https://cdn.shopify.com/s/files/1/0493/1102/3270/files/bagagagowevewizosoparifa.pdf
- https://cdn.shopify.com/s/files/1/0440/8282/3333/files/5236086031.pdf
- https://cdn.shopify.com/s/files/1/0429/7208/6435/files/vc_generator_2k16_no_survey.pdf
- https://cdn.shopify.com/s/files/1/0433/2440/7961/files/miley_cyrus_diet_menu.pdf
- https://cdn.shopify.com/s/files/1/0487/0098/1398/files/tascam_dr40x_4-track_audio_recorder.pdf
- https://cdn.shopify.com/s/files/1/0493/2186/9471/files/pukawejixufebadalidusi.pdf
- https://cdn.shopify.com/s/files/1/0499/2873/2830/files/morozewevojusewa.pdf
- https://cdn.shopify.com/s/files/1/0436/6431/0425/files/54535419497.pdf
Embedded domains
- gettraff.ru
- site-1038555.mozfiles.com
- site-1038790.mozfiles.com
- site-1040376.mozfiles.com
- site-1043176.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report