SUSPICIOUS — method_of_movement_for_marimba_with_590_exercises.pdf
SUSPICIOUS — method_of_movement_for_marimba_with_590_exercises.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
69a0add059d41a5aa833b3456e48cc33c67578a06ac6823da42a8177be38de58 - SHA-1:
5d2b44ca8703e70f02ed668ff6f8df58ec33d495 - MD5:
e5dae1edf32d488083f7329406063744 - ssdeep:
768:IgGzpD9spvoxxypyB1TzR6u1kL5v0oBQqZwQ4ibQ:FGFBspo1QZBRZV4ibQ - TLSH:
T1FF307BF750A7DD4C7A879713BDBA291A6589C38C6222D72045DC7B2CC4BC6BE7E10821 - Submitted as: method_of_movement_for_marimba_with_590_exercises.pdf
- File type: pdf · Size: 36522 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=method+of+movement+for+marimba+with+590+exercises, https://cdn-cms.f-static.net/uploads/4365555/normal_5f8d140f3044e.pdf, https://cdn-cms.f-static.net/uploads/4369651/normal_5f89150294191.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=method+of+movement+for+marimba+with+590+exercises
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f8d140f3044e.pdf
- https://cdn-cms.f-static.net/uploads/4369651/normal_5f89150294191.pdf
- https://cdn-cms.f-static.net/uploads/4376358/normal_5f8a9450bc2f9.pdf
- https://cdn.shopify.com/s/files/1/0497/3189/5457/files/75466167490.pdf
- https://cdn.shopify.com/s/files/1/0463/2166/4160/files/89190969130.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/37859407159.pdf
- https://cdn.shopify.com/s/files/1/0484/6898/3969/files/83143327061.pdf
- https://cdn.shopify.com/s/files/1/0435/7180/6366/files/vudu_movies_missing_from_movies_anywhere.pdf
- https://uploads.strikinglycdn.com/files/aa697f8d-f183-46f1-ab0b-36b59e5622df/88936803677.pdf
- https://uploads.strikinglycdn.com/files/c63e5498-d5ab-4b25-9fb8-806b8c220fd4/rejimomaluse.pdf
- https://uploads.strikinglycdn.com/files/564f7d2a-b679-4c30-bcff-180e82603f45/fejesoketik.pdf
- https://biwugina.weebly.com/uploads/1/3/1/1/131163984/4721261.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/44d87feaf8ee.pdf
- https://ruwopevod.weebly.com/uploads/1/3/1/3/131397973/tulozajew.pdf
- https://lokixesope.weebly.com/uploads/1/3/1/6/131607163/1526823.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f87e37403cf7.pdf
- https://cdn-cms.f-static.net/uploads/4368750/normal_5f883c43c1eae.pdf
- https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/tisaxuwabu.pdf
- https://vodiwisilob.weebly.com/uploads/1/3/2/6/132681054/mipakowavovivajabi.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/zerugijo_kebejanukuxu_gonejad.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- biwugina.weebly.com
- mojivimimujovo.weebly.com
- ruwopevod.weebly.com
- lokixesope.weebly.com
- mefemanodi.weebly.com
- vodiwisilob.weebly.com
- dejolezeg.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report