SUSPICIOUS — gw2_revenant_weapon_guide.pdf
SUSPICIOUS — gw2_revenant_weapon_guide.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
234bc5d3a94c9237d27060122c760360a44e001145f674af89fbf42e5fdaa79c - SHA-1:
896a20d8980ca8519fa95a803a6ac685782b614e - MD5:
e0d67a32bebdc90ee0f9b53126b1a4e8 - ssdeep:
768:TgGzpDFpCg+wbeSufLHbw6hZANP61pIJbAn0hw7BAuKLjPbJeQn0DzgOHrl:sGFxpl9O66pYA4wBAuKfP1jnwgOHrl - TLSH:
T1D633AEF31463EC8C7ACAAB43EDA71569608BC74C6126EB6054DC762CD4BC6BC6E10960 - Submitted as: gw2_revenant_weapon_guide.pdf
- File type: pdf · Size: 49986 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=gw2+revenant+weapon+guide, https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/xekena.pdf, https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/kamekelubabutuz_wovafokiwatipep.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=gw2+revenant+weapon+guide
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/xekena.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/kamekelubabutuz_wovafokiwatipep.pdf
- https://nagifinapu.weebly.com/uploads/1/3/2/6/132696111/sodujifezulojut.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/tugunari_fogeze_nezejavoz.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/zuvekazabuz-topofelo-gupolekodojavo-ponabiloxe.pdf
- https://cdn.shopify.com/s/files/1/0495/9584/2709/files/bergen_county_newspapers.pdf
- https://cdn.shopify.com/s/files/1/0483/7261/3280/files/zepak.pdf
- https://cdn.shopify.com/s/files/1/0501/8723/9597/files/sekivizasexeko.pdf
- https://cdn.shopify.com/s/files/1/0431/2167/2356/files/xetajidusugijaz.pdf
- https://cdn.shopify.com/s/files/1/0499/5465/2309/files/the_story_of_halloween.pdf
- https://uploads.strikinglycdn.com/files/817ea3ea-495d-4120-bc22-fe67589a6cce/81311384727.pdf
- https://uploads.strikinglycdn.com/files/747378be-bdf4-42d5-8de2-29c4513cecea/79815766012.pdf
- https://uploads.strikinglycdn.com/files/2868c930-43dd-4e93-8d33-234429fbe745/61638013656.pdf
- https://uploads.strikinglycdn.com/files/127a09dd-34c7-4c51-a2b7-812f7bd024da/30491284267.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/lininofabened.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/domovodibaposix.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/5094659.pdf
- https://pidofuvu.weebly.com/uploads/1/3/0/7/130739764/9962651.pdf
- https://cdn.shopify.com/s/files/1/0482/7224/4900/files/sozavafoj.pdf
- https://cdn.shopify.com/s/files/1/0500/0524/6112/files/80015064324.pdf
- https://cdn.shopify.com/s/files/1/0482/9439/6068/files/45893348954.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- xojerajap.weebly.com
- genigudepa.weebly.com
- nagifinapu.weebly.com
- guwomenod.weebly.com
- fodezamu.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- lagukekejase.weebly.com
- pidofuvu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report