SUSPICIOUS — body_for_life_food_list.pdf
SUSPICIOUS — body_for_life_food_list.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
2d2b35917527354a58dbc14ac06d1485b2ef67ad6ca85a7dd62039df5ae675f4 - SHA-1:
1bdbc2040ab2ef34a0a32d2ad19f8843f0a5a26d - MD5:
9a38b4c7af60d261eebc662ce98a115d - ssdeep:
768:kgGzpDEp0hcC72YWWC3DX2AfUiTJ7ldhH4Skz6WOGTUqxrBoTft0B1:RGFwpntlPrWOGTUq1BoTV0B1 - TLSH:
T1E3328EF34093ED8C7A4F7B039AAB11AD508ED78D60369B60548C672CD47C6ED6F00A65 - Submitted as: body_for_life_food_list.pdf
- File type: pdf · Size: 45480 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=body+for+life+food+list+pdf, https://cdn.shopify.com/s/files/1/0496/0809/7956/files/medea_themes_shmoop.pdf, https://cdn.shopify.com/s/files/1/0437/9371/1265/files/algorithm_design_manual_exercise_solutions.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=body+for+life+food+list+pdf
- https://cdn.shopify.com/s/files/1/0496/0809/7956/files/medea_themes_shmoop.pdf
- https://cdn.shopify.com/s/files/1/0437/9371/1265/files/algorithm_design_manual_exercise_solutions.pdf
- https://cdn.shopify.com/s/files/1/0437/8591/2477/files/4147318705.pdf
- https://cdn.shopify.com/s/files/1/0502/4651/6898/files/wikujejonipezasuxudo.pdf
- https://cdn.shopify.com/s/files/1/0496/1527/4147/files/un_manual_para_ser_nio_gabriel_garcia_marquez.pdf
- https://cdn-cms.f-static.net/uploads/4368999/normal_5f8937b68b293.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f89fd557f0bc.pdf
- https://cdn-cms.f-static.net/uploads/4374545/normal_5f8a0dbed77bd.pdf
- https://cdn-cms.f-static.net/uploads/4367017/normal_5f88013acab90.pdf
- https://cdn-cms.f-static.net/uploads/4369935/normal_5f88bd66067ac.pdf
- https://uploads.strikinglycdn.com/files/9e0fc293-e7b0-448f-83fb-be9dbdb32a87/88820922212.pdf
- https://uploads.strikinglycdn.com/files/ec235430-3e0f-4346-b480-bb29ca384242/363418924.pdf
- https://uploads.strikinglycdn.com/files/0b5f6d8c-2e5c-4263-ba94-326f9775faba/nupamuxuwab.pdf
- https://uploads.strikinglycdn.com/files/75b88c29-1f4f-49e4-850a-2e1652f2a644/17669442324.pdf
- https://uploads.strikinglycdn.com/files/09cce52d-fbf0-44eb-9b93-3c9a1d9aa56a/musabire.pdf
- https://uploads.strikinglycdn.com/files/6e6fc220-beec-4d68-8858-029b79e9e529/sagaje.pdf
- https://uploads.strikinglycdn.com/files/9820bfd2-75b0-4203-8195-48f08d7b3615/77707149071.pdf
- https://uploads.strikinglycdn.com/files/df5fa80c-c3e0-417b-9783-b532fe450b66/xituwoxu.pdf
- https://uploads.strikinglycdn.com/files/09410d77-2618-401b-bb01-f8dbcdf60337/vusadexesejo.pdf
- https://cdn-cms.f-static.net/uploads/4369160/normal_5f87f33f8372f.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f87433f7bac0.pdf
- https://uploads.strikinglycdn.com/files/0cf5e0b2-a1d6-4a55-a141-2c44daeba01d/63659957006.pdf
- https://uploads.strikinglycdn.com/files/d21b446b-10f4-4259-9660-3ee97fed48f4/26442188048.pdf
- https://uploads.strikinglycdn.com/files/12514b4c-695f-4297-b687-56c7b4e6832c/zidifipezugi.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report