SUSPICIOUS — lizel.pdf
SUSPICIOUS — lizel.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
bbd8227a18afdcac3bf310e0336e0a8130b02331575c61b7f96ab2f947fbe354 - SHA-1:
7440a40b4a16549e757a6759707c787d2f1c72b9 - MD5:
b727420579146fc633ea8319f19e1dc3 - ssdeep:
768:7gGzpDpp1CT0d7gzxzbFR/LzXOYSI1T4j3pw59A95zahufVNr6TeqTOVm4mm5:EGF1p1JidHXOYSISLpwDClahudNkeoOd - TLSH:
T174328DF31053ED8C7B8BAB47ADA61149E04AC3C96167D76014C876ACD9B86FE7F00960 - Submitted as: lizel.pdf
- File type: pdf · Size: 45410 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=tendencias%20pedagogicas%20contemporaneas%20ppt, https://uploads.strikinglycdn.com/files/a239c59e-0197-4f97-bee1-3a201ac19e04/lelaliniwalufulagijexuw.pdf, https://uploads.strikinglycdn.com/files/be9e8711-85a3-4c1b-bba2-5740d2bb513d/69028269515.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=tendencias%20pedagogicas%20contemporaneas%20ppt
- https://uploads.strikinglycdn.com/files/a239c59e-0197-4f97-bee1-3a201ac19e04/lelaliniwalufulagijexuw.pdf
- https://uploads.strikinglycdn.com/files/be9e8711-85a3-4c1b-bba2-5740d2bb513d/69028269515.pdf
- https://uploads.strikinglycdn.com/files/94f75f6d-d801-43fd-ada5-646ca2ee8df4/84420106387.pdf
- https://uploads.strikinglycdn.com/files/c4b36f3e-b829-4341-838a-d4eac8750633/96237200199.pdf
- https://cdn.shopify.com/s/files/1/0434/2172/8919/files/lubuzumedutokigapigalem.pdf
- https://cdn.shopify.com/s/files/1/0479/8074/0771/files/plate_tectonics_worksheets_for_middle_school.pdf
- https://cdn.shopify.com/s/files/1/0503/8057/0811/files/common_phrasal_verbs_in_english.pdf
- https://cdn.shopify.com/s/files/1/0486/6162/7048/files/49187717938.pdf
- https://cdn.shopify.com/s/files/1/0435/5407/8871/files/nyc_public_school_calendar_2015.pdf
- https://cdn.shopify.com/s/files/1/0486/0182/5448/files/funny_running_man_episodes_no_guest.pdf
- https://uploads.strikinglycdn.com/files/bf6879e7-8134-43d2-a8f4-2e245fb7b5d9/87646682224.pdf
- https://uploads.strikinglycdn.com/files/329a05fc-b442-466b-b2d5-0f813a9cd63b/67531572727.pdf
- https://xujaxivef.weebly.com/uploads/1/3/1/4/131438557/6b06e.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/digokasawuj-jipamuputevuf.pdf
- https://s3.amazonaws.com/gupuso/kigusopixejepalonitifojun.pdf
- https://s3.amazonaws.com/felasorarabipis/sunisudadonudubexew.pdf
- https://s3.amazonaws.com/fasanag/direct_and_indirect_expenses_in_accounting.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- xujaxivef.weebly.com
- keniwuki.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report