SUSPICIOUS — lisaxidokavotu.pdf
SUSPICIOUS — lisaxidokavotu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ed0f5690f357f3df0f951e6cc55fcd8b04129263face8b8c4aba258fe376cc11 - SHA-1:
0d85a9ff4100b1a8e502e439054e1463ece0eb9c - MD5:
27f8a3afce72e37fc0f5c22ac8d0cc81 - ssdeep:
1536:nGFUpRiWxiA/b3ra8TKMhvpQaaNTpgELESfMk9GmgP:GFUpRioik7ra8WEvpQaaNmIE37 - TLSH:
T1FD35B0F35067DC8C398BAF03ADFA245D614DE789A132AB20598C732CD4BC2AD7E50551 - Submitted as: lisaxidokavotu.pdf
- File type: pdf · Size: 61029 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=robert%20greene%20las%2033%20estrategias%20de%20la%20guerra%20pdf, https://cdn.shopify.com/s/files/1/0503/8650/1806/files/napkin_rings_ebay_australia.pdf, https://cdn.shopify.com/s/files/1/0437/8682/9981/files/21970043722.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=robert%20greene%20las%2033%20estrategias%20de%20la%20guerra%20pdf
- https://cdn.shopify.com/s/files/1/0503/8650/1806/files/napkin_rings_ebay_australia.pdf
- https://cdn.shopify.com/s/files/1/0437/8682/9981/files/21970043722.pdf
- https://cdn.shopify.com/s/files/1/0497/4362/6403/files/bejojimatub.pdf
- https://cdn.shopify.com/s/files/1/0427/9464/7719/files/lemekideruzasaluke.pdf
- https://cdn.shopify.com/s/files/1/0487/0507/7398/files/proto_socket_set_review.pdf
- https://cdn.shopify.com/s/files/1/0484/9929/4363/files/39799165955.pdf
- https://cdn.shopify.com/s/files/1/0430/6799/8359/files/bulkeley_high_school_wikipedia.pdf
- https://uploads.strikinglycdn.com/files/c9bdbffc-9d83-422a-8ae2-71a5bcccb606/kemisupuwojuvigiwawolibi.pdf
- https://uploads.strikinglycdn.com/files/b6caa986-f7d5-4b52-8b12-737a5db9d507/25999858551.pdf
- https://uploads.strikinglycdn.com/files/a9f5db05-8a51-4fd8-b246-f6b2d56e93f5/sivafulizidudololodo.pdf
- https://uploads.strikinglycdn.com/files/47c811e5-769b-40f7-86d6-d1a128b8ea6e/werunizizevexekixan.pdf
- https://cdn-cms.f-static.net/uploads/4384029/normal_5f8d2d3b4443f.pdf
- https://cdn-cms.f-static.net/uploads/4369158/normal_5f8d3a3c4c9c0.pdf
- https://cdn-cms.f-static.net/uploads/4378379/normal_5f89fd5b53799.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f884fa7bcb9d.pdf
- https://cdn-cms.f-static.net/uploads/4369923/normal_5f89755015e26.pdf
- https://cdn.shopify.com/s/files/1/0432/3357/5075/files/30429022797.pdf
- https://cdn.shopify.com/s/files/1/0488/0623/2229/files/4.3_arithmetic_and_geometric_sequence_worksheet_answers.pdf
- https://fosogaji.weebly.com/uploads/1/3/1/4/131455903/8e41934678e53.pdf
- https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/62ca8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- fosogaji.weebly.com
- vikumeniwexawud.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report