SUSPICIOUS — salon_policy_and_procedure_manual.pdf
SUSPICIOUS — salon_policy_and_procedure_manual.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
52c2e491182112a9102b97106fce9699c18f040011ec8427c4b304a328bbd602 - SHA-1:
ba9346bd10ff67af4313f63f288d9f4ee526e006 - MD5:
4fd2122439d673ec454d8b6271f0ae25 - ssdeep:
768:rgGzpDAP7lh2qTSNWn4hHEyrnATLljYGpYGmZvbZYhc5A88XvkGghyd0I46MBs:UGFkn4ijbu3vbChca88XIySV6MBs - TLSH:
T1BC328FF31093ED8C3A8AAF53AEBA151D558AD74D6036E7640888772CE57C6BD7F00860 - Submitted as: salon_policy_and_procedure_manual.pdf
- File type: pdf · Size: 45458 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=salon+policy+and+procedure+manual, https://cdn.shopify.com/s/files/1/0440/3652/2149/files/iron_defender_drop_rate_osrs.pdf, https://uploads.strikinglycdn.com/files/67d7f2b5-d3b3-4a2a-a599-6cc599ac1ac0/14975113109.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=salon+policy+and+procedure+manual
- https://cdn.shopify.com/s/files/1/0440/3652/2149/files/iron_defender_drop_rate_osrs.pdf
- https://uploads.strikinglycdn.com/files/67d7f2b5-d3b3-4a2a-a599-6cc599ac1ac0/14975113109.pdf
- https://cdn.shopify.com/s/files/1/0484/4909/3797/files/iceland_tourist_map.pdf
- https://uploads.strikinglycdn.com/files/3ac37721-9dcf-4c74-a239-f7968b801821/que_es_situacion_comunicativa.pdf
- https://s3.amazonaws.com/xipavir/77936285394.pdf
- https://cdn.shopify.com/s/files/1/0484/0829/7624/files/depil.pdf
- https://uploads.strikinglycdn.com/files/02af678a-cd7b-4624-8b2b-7e9b59b039a4/una_mecanica_sin_talachas_resumen_capitulo_5.pdf
- https://uploads.strikinglycdn.com/files/5e9c7567-b2c0-4098-9c9b-599fc5f07a1f/wasasaxewudisupurujavoko.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f8724badec59.pdf
- https://uploads.strikinglycdn.com/files/383cc612-4c8e-4055-880d-9cec454aad6f/kawedipebenibuzekebeva.pdf
- https://cdn-cms.f-static.net/uploads/4370071/normal_5f8d2e89d6229.pdf
- https://cdn.shopify.com/s/files/1/0497/6007/5930/files/jedepudusiw.pdf
- https://cdn-cms.f-static.net/uploads/4384152/normal_5f963532c4846.pdf
- https://cdn.shopify.com/s/files/1/0432/1692/8923/files/95351295419.pdf
- https://uploads.strikinglycdn.com/files/f3f10e85-26c1-4bad-a9ac-d1c8b8a11800/67794177245.pdf
- https://cdn-cms.f-static.net/uploads/4369648/normal_5f9262301b7a4.pdf
- https://s3.amazonaws.com/wazorixekunafob/capites_de_areia_jorge_amado.pdf
- https://uploads.strikinglycdn.com/files/533b4a08-d524-433c-a777-ed07a8e0c957/vikings_training_camp_schedule_2019.pdf
- https://cdn.shopify.com/s/files/1/0493/5673/4630/files/cedar_falls_high_school_football.pdf
- https://s3.amazonaws.com/tetazino/ccna_200-_125_exam_free_download.pdf
- https://uploads.strikinglycdn.com/files/ff7e7fca-fe6a-4097-9ff8-de8a0a14399c/56188378796.pdf
- https://uploads.strikinglycdn.com/files/6b44ff68-3325-45eb-97a2-c64da05e1f81/negideboxelelezupalel.pdf
- https://cdn.shopify.com/s/files/1/0266/8511/2496/files/average_speed_problems_worksheet_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0488/0200/5157/files/dragon_ball_z_fighting_games_apk_download.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report