SUSPICIOUS — 11046245784.pdf
SUSPICIOUS — 11046245784.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1e319c0f580916b2858a0bbb52020c5cd18655ee10f19a2964e483ab80ac9a2d - SHA-1:
834099c335609620125779b77865235f7220d279 - MD5:
883a285569f8969593caade9d1c9d39c - ssdeep:
768:wgGzpDDO5eMJ4nwJHb1QHuityTxGomI2zjz3/Zqe1AQkAjA:dGFvO0MJ44jnmvzjzvgcAQkAjA - TLSH:
T10131AEF350A7DD4D3A8EDB0779B2115A6449C68CA032EA60188C773CD47C6FEAE10A61 - Submitted as: 11046245784.pdf
- File type: pdf · Size: 43007 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=usha+janome+sewing+machine+repair+manual, https://cdn.shopify.com/s/files/1/0501/3399/1612/files/lixulom.pdf, https://uploads.strikinglycdn.com/files/890d0cd1-944b-4cae-9695-7f71a59a598d/14211142837.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=usha+janome+sewing+machine+repair+manual
- https://cdn.shopify.com/s/files/1/0501/3399/1612/files/lixulom.pdf
- https://s3.amazonaws.com/zinudipir/zademebebebavikadenu.pdf
- https://uploads.strikinglycdn.com/files/890d0cd1-944b-4cae-9695-7f71a59a598d/14211142837.pdf
- https://s3.amazonaws.com/ronenitevodo/83592152899.pdf
- https://rogusedi.weebly.com/uploads/1/3/4/4/134433103/moberaju_salomawep_xesetunubokola_tujor.pdf
- https://xinusikavafomi.weebly.com/uploads/1/3/4/3/134353784/narotuzudimuj_wudamagudevu_zafoxela_buxuwusuwabir.pdf
- https://uploads.strikinglycdn.com/files/7e6a2d90-b86d-400d-906a-56e6dd5f5261/43975166296.pdf
- https://cdn.shopify.com/s/files/1/0434/7658/2552/files/bending_moment_equation.pdf
- https://cdn.shopify.com/s/files/1/0501/7757/3040/files/ebay_desktop_site_on_android.pdf
- https://cdn.shopify.com/s/files/1/0433/8240/7318/files/2559366255.pdf
- https://nobaditidiz.weebly.com/uploads/1/3/4/2/134235496/5385581.pdf
- https://cdn.shopify.com/s/files/1/0266/9006/0488/files/4212323171.pdf
- https://cdn.shopify.com/s/files/1/0476/9307/0502/files/thermal_energy_formula_thermodynamics.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- rogusedi.weebly.com
- xinusikavafomi.weebly.com
- nobaditidiz.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report