SUSPICIOUS — jerarquia_de_operaciones_aritmeticas.pdf
SUSPICIOUS — jerarquia_de_operaciones_aritmeticas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
19b145892c0862c7f7971250cb609415fe8c41e17bcc82092d7ad3e123d2b6c0 - SHA-1:
d41ddb1f034e34701525a5901f39920a2f460b24 - MD5:
a40749fdc5e625e0b87d7c23375aefd7 - ssdeep:
768:0gGzpDip3liNn8X61xCAWzNy5WQEXMSiLH2dYfnOMDj/19HWi+ZAPHrFXJhAKjMs:BGF+pIHjsYfnj19D4KJ8NB+jm7Ch7 - TLSH:
T1B0339DF31097ED8D3A879F836CAB118A6046D788B136A6A1028C7B2CD57C5FCBF40561 - Submitted as: jerarquia_de_operaciones_aritmeticas.pdf
- File type: pdf · Size: 48906 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=jerarquia+de+operaciones+aritmeticas, https://cdn.shopify.com/s/files/1/0434/6209/9097/files/simunadiralo.pdf, https://cdn.shopify.com/s/files/1/0501/4247/8501/files/ge_profile_microwave_advantium_120_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=jerarquia+de+operaciones+aritmeticas
- https://cdn.shopify.com/s/files/1/0434/6209/9097/files/simunadiralo.pdf
- https://cdn.shopify.com/s/files/1/0501/4247/8501/files/ge_profile_microwave_advantium_120_manual.pdf
- https://cdn.shopify.com/s/files/1/0483/8929/2184/files/sejinosipa.pdf
- https://ziperivowupidu.weebly.com/uploads/1/3/1/3/131381589/8296964.pdf
- https://cdn.shopify.com/s/files/1/0492/8225/2957/files/58730359513.pdf
- https://cdn.shopify.com/s/files/1/0430/1442/2677/files/the_corfu_trilogy_amazon.pdf
- https://cdn-cms.f-static.net/uploads/4374376/normal_5f8958d1ef15a.pdf
- https://cdn-cms.f-static.net/uploads/4373509/normal_5f89bb9873234.pdf
- https://cdn-cms.f-static.net/uploads/4368225/normal_5f87a165a6ad5.pdf
- https://cdn.shopify.com/s/files/1/0491/8483/3702/files/bobizadelez.pdf
- https://cdn.shopify.com/s/files/1/0266/9481/1836/files/clear_outlook_cache_windows.pdf
- https://cdn.shopify.com/s/files/1/0500/1392/9630/files/advanced_image_search_android.pdf
- https://cdn.shopify.com/s/files/1/0500/6560/4766/files/50998764994.pdf
- https://cdn.shopify.com/s/files/1/0435/3343/5039/files/sabal_point_elementary_school_rating.pdf
- https://cdn.shopify.com/s/files/1/0484/5168/2454/files/volanijibojetutoxoteta.pdf
- https://cdn.shopify.com/s/files/1/0482/3603/6256/files/town_hall_9_war_base_download.pdf
- https://cdn.shopify.com/s/files/1/0268/7801/7724/files/36944614035.pdf
- https://cdn.shopify.com/s/files/1/0438/1101/2770/files/dobatinimutotukuzed.pdf
- https://cdn.shopify.com/s/files/1/0500/1392/9630/files/19339774164.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- ziperivowupidu.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report