SUSPICIOUS — zizelox.pdf
SUSPICIOUS — zizelox.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7b3cb13b1ab245954a8084ca79c0b7e465d89c64bdc77d42bf7bc85aa34666da - SHA-1:
a514dcb0db836ff2bdd63c009e163c4fd417d3d5 - MD5:
1adfef75a95fd743dcfad70182523d8a - ssdeep:
768:vgGzpD1pyHjYZR4qIP0XRTVne11apode1zXSOP2j2Ri7Nv930PXp6pPfXBTO:YGF5pRpodor5PBOR9esXBTO - TLSH:
T18F318DF354D7EC8C7E865B03ADAB15E66049C68D3132A66055CC7B2CC8BC6FDAE10960 - Submitted as: zizelox.pdf
- File type: pdf · Size: 42520 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=folder%20mockup%20template%20photoshop, https://cdn-cms.f-static.net/uploads/4365600/normal_5f8700ace8617.pdf, https://cdn-cms.f-static.net/uploads/4366005/normal_5f878b75b5e74.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=folder%20mockup%20template%20photoshop
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f8700ace8617.pdf
- https://cdn-cms.f-static.net/uploads/4366005/normal_5f878b75b5e74.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f874c2a04fe7.pdf
- https://cdn.shopify.com/s/files/1/0462/3876/1109/files/square_numbers_worksheet_5th_grade.pdf
- https://cdn.shopify.com/s/files/1/0482/5386/2042/files/grizzly_g7943_canada.pdf
- https://cdn.shopify.com/s/files/1/0501/1393/7573/files/46412986760.pdf
- https://cdn.shopify.com/s/files/1/0491/7886/9926/files/texikibenisazinojovot.pdf
- https://dirigesibujov.weebly.com/uploads/1/3/0/9/130969991/4913953.pdf
- https://buluzuzumaz.weebly.com/uploads/1/3/1/6/131636727/6110784.pdf
- https://bezebaterizijir.weebly.com/uploads/1/3/1/3/131384714/7552393.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f875856948f1.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f87443daf55f.pdf
- https://cdn-cms.f-static.net/uploads/4379611/normal_5f8b11c7debb0.pdf
- https://uploads.strikinglycdn.com/files/68f6c560-ff46-4217-93d0-b5bc875a85e4/28434697290.pdf
- https://uploads.strikinglycdn.com/files/3a714204-ed96-4ad6-b1e0-90bd59dc43ca/41016477168.pdf
- https://uploads.strikinglycdn.com/files/4fb20b75-e643-47b2-b186-904ff689fb23/banagifuzopupurovorulale.pdf
- https://uploads.strikinglycdn.com/files/49e7f846-8218-438e-92d7-aca4063df104/98702340250.pdf
- https://bewapuvin.weebly.com/uploads/1/3/1/4/131453684/5e3bc144d4d09.pdf
- https://senobatupubem.weebly.com/uploads/1/3/1/4/131437889/banezajit.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/nutogeboxisujimerujo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- dirigesibujov.weebly.com
- buluzuzumaz.weebly.com
- bezebaterizijir.weebly.com
- uploads.strikinglycdn.com
- bewapuvin.weebly.com
- senobatupubem.weebly.com
- boguvetasitob.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report