SUSPICIOUS — 41144476042.pdf
SUSPICIOUS — 41144476042.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4fda125dbac765450659db12a73b2d543e7f2ee0c91d486e0fa7c75e483b42a6 - SHA-1:
b153ea14fa58abe5ffbc080cd3e295a0d1c36a30 - MD5:
c8f594025c54e8bb2a0e421ceaee37ac - ssdeep:
768:jgGzpDUXBlaJCJvyCp6KlrOE2e9l7HiObqWwwgM:cGFIXGgYKNOj47HiYwwgM - TLSH:
T16A309EF35497DD8D7AC69B039CAB0069108AC2897272A6A419DC3B7ED4BC5BD7E10870 - Submitted as: 41144476042.pdf
- File type: pdf · Size: 36985 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=awei+t5+manual+pdf, https://site-1038874.mozfiles.com/files/1038874/godusizijur.pdf, https://site-1037251.mozfiles.com/files/1037251/jasobagaliwabubudavul.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=awei+t5+manual+pdf
- https://site-1038874.mozfiles.com/files/1038874/godusizijur.pdf
- https://site-1037251.mozfiles.com/files/1037251/jasobagaliwabubudavul.pdf
- https://site-1037048.mozfiles.com/files/1037048/ligejakigof.pdf
- https://uploads.strikinglycdn.com/files/ec7afdca-2d4a-4478-9c2e-639f0396dfb3/40014133946.pdf
- https://uploads.strikinglycdn.com/files/d19c16a7-738e-4f02-ae98-11ebad2f874c/20553486876.pdf
- https://uploads.strikinglycdn.com/files/b19913ed-6861-4a8e-b975-3b05def6b2af/movona.pdf
- https://uploads.strikinglycdn.com/files/12649767-d210-4171-b19c-266e299bd9e0/pegaxa.pdf
- https://uploads.strikinglycdn.com/files/a1db2894-7274-42c2-a33b-15eb481d2105/76299632876.pdf
- http://files.chennaitiffinssandiego.us/uploads/1/3/0/8/130813934/926b3ba66.pdf
- http://rebale.chelseafarmersmarket.org/uploads/1/3/1/0/131071164/8a4e48a.pdf
- http://petuti.mayfieldwoodsorchestra.com/uploads/1/3/1/8/131856072/5882853.pdf
- https://cdn.shopify.com/s/files/1/0429/0586/2307/files/77202990712.pdf
- https://cdn.shopify.com/s/files/1/0484/7448/8982/files/2018_ap_calculus_bc_free_response_5.pdf
- https://cdn.shopify.com/s/files/1/0429/6530/3455/files/motorola_ap_7532_manual.pdf
- https://cdn.shopify.com/s/files/1/0430/3123/2674/files/gmail_app_dark_mode_android_9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1038874.mozfiles.com
- site-1037251.mozfiles.com
- site-1037048.mozfiles.com
- uploads.strikinglycdn.com
- files.chennaitiffinssandiego.us
- rebale.chelseafarmersmarket.org
- petuti.mayfieldwoodsorchestra.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report