SUSPICIOUS — guzuk.pdf
SUSPICIOUS — guzuk.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
56a85aacd7ff67f7fa65f7226bc9445bd74b6e1cefb7452035e85c61bf7bdc95 - SHA-1:
b5a820ae79f7986748ad01d455037c937c2335e2 - MD5:
eccafb94cd8ca93af0a750ba8e1bcfff - ssdeep:
1536:/GF1pUhc3mnDv1rq551O0c0u9bgsQSQPA+jCS59Op7gos84S2HtFTdppX:uF1pUhcMv1rU51O0bu90NSB+dup7Z2NP - TLSH:
T15637C0F3619BED8CBA8F6B479DEB0569508EC748A032979014487B2DC4BC9FC6F14A11 - Submitted as: guzuk.pdf
- File type: pdf · Size: 70530 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=tekken%207%20top%2015%20moves%20for%20all%20charac, https://site-1041404.mozfiles.com/files/1041404/93083154333.pdf, https://site-1043534.mozfiles.com/files/1043534/list_of_narrative_techniques_in_literature.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=tekken%207%20top%2015%20moves%20for%20all%20charac
- https://site-1041404.mozfiles.com/files/1041404/93083154333.pdf
- https://site-1043534.mozfiles.com/files/1043534/list_of_narrative_techniques_in_literature.pdf
- https://site-1043791.mozfiles.com/files/1043791/8695577021.pdf
- https://site-1036935.mozfiles.com/files/1036935/jomalaxegasavu.pdf
- https://site-1038789.mozfiles.com/files/1038789/lenuk.pdf
- https://uploads.strikinglycdn.com/files/1e0f8c81-ed8b-4c69-815f-5fdec2c48ba2/28393432400.pdf
- https://uploads.strikinglycdn.com/files/ef3b59e2-198f-4640-8526-8e29eb7b2b86/52803115091.pdf
- https://cdn-cms.f-static.net/uploads/4366952/normal_5f8747b4265de.pdf
- https://cdn-cms.f-static.net/uploads/4367622/normal_5f87526ad48d3.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f877703650ed.pdf
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f878b471d65e.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f87a49e708dd.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f871c644574a.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f87596fea60e.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f87cfb1b8e1e.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f8738e2a6952.pdf
- https://cdn.shopify.com/s/files/1/0485/0863/3243/files/95964949192.pdf
- https://cdn.shopify.com/s/files/1/0488/4447/2485/files/shed_ramp_kits_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0481/4353/2185/files/90956039897.pdf
- https://cdn.shopify.com/s/files/1/0476/7327/8630/files/63249304800.pdf
- https://cdn.shopify.com/s/files/1/0268/7795/2169/files/vanuseluz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- site-1041404.mozfiles.com
- site-1043534.mozfiles.com
- site-1043791.mozfiles.com
- site-1036935.mozfiles.com
- site-1038789.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report