SUSPICIOUS — 7098574868.pdf
SUSPICIOUS — 7098574868.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0c9ed7c0257ec2683126b44009e32d0d2d4a13866199b0548004801dc78f9b6b - SHA-1:
68311e6f3e77db94e1b56264945673cbf0822985 - MD5:
afa230542736c6d2dd0ee91568533676 - ssdeep:
768:3ygGzpDiekaifrA0T4nX2X3E1GcSXaCVtsZFDE31LGwvWM5Ncl+uaA2dTasV5CVK:fGFeey454U435+faA2NasV5gOYS1 - TLSH:
T167337DF321A7DD8C77CAAB0769B6109D614AC7497032DBA04988AB2CC57C6FD7E00A51 - Submitted as: 7098574868.pdf
- File type: pdf · Size: 51626 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=como+usar+presets+no+lightroom+celular+android, https://cdn.shopify.com/s/files/1/0438/9512/8216/files/the_courage_to_teach_chapter_1_summary.pdf, https://cdn.shopify.com/s/files/1/0434/7337/1300/files/migusulugugowejipetub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=como+usar+presets+no+lightroom+celular+android
- https://cdn.shopify.com/s/files/1/0492/1986/2694/files/konemegazupare.pdf
- https://cdn.shopify.com/s/files/1/0438/9512/8216/files/the_courage_to_teach_chapter_1_summary.pdf
- https://cdn.shopify.com/s/files/1/0434/7337/1300/files/migusulugugowejipetub.pdf
- https://cdn.shopify.com/s/files/1/0492/4447/1452/files/singer_advance_sewing_machine_manual.pdf
- https://cdn-cms.f-static.net/uploads/4366627/normal_5f8751ec80674.pdf
- https://cdn-cms.f-static.net/uploads/4366660/normal_5f87cf1981486.pdf
- https://site-1044026.mozfiles.com/files/1044026/5973416344.pdf
- https://site-1043170.mozfiles.com/files/1043170/kejimegavuwejik.pdf
- https://site-1037907.mozfiles.com/files/1037907/7014188960.pdf
- https://site-1036946.mozfiles.com/files/1036946/39279322778.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/zikarab.pdf
- https://pejapuvurexoku.weebly.com/uploads/1/3/1/6/131636728/vipesapozimenabisasu.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3532345.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/wijiliso.pdf
- https://lixaworone.weebly.com/uploads/1/3/1/8/131871871/c8a358dd5c9b.pdf
- https://xanodupujariris.weebly.com/uploads/1/3/0/9/130969381/cc60ce86063c.pdf
- https://cdn.shopify.com/s/files/1/0501/4247/8501/files/43689747410.pdf
- https://cdn.shopify.com/s/files/1/0498/5926/4674/files/pso2_unit_affixing_guide.pdf
- https://cdn.shopify.com/s/files/1/0438/4768/0162/files/dewalt_dw708_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0429/5006/6339/files/skin_color_code_photoshop.pdf
- https://cdn.shopify.com/s/files/1/0266/8671/8129/files/hurst_beans_slow_cooker.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1044026.mozfiles.com
- site-1043170.mozfiles.com
- site-1037907.mozfiles.com
- site-1036946.mozfiles.com
- dutitujazekap.weebly.com
- pejapuvurexoku.weebly.com
- zoxuzuxebexot.weebly.com
- dapujevubo.weebly.com
- lixaworone.weebly.com
- xanodupujariris.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report