SUSPICIOUS — visual_land_prestige_elite_9q_troubleshooting.pdf
SUSPICIOUS — visual_land_prestige_elite_9q_troubleshooting.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6b1e224c816c4d9ceeb2fd4ab0aea529b439a09cd3d645a8959dcdbb36b15237 - SHA-1:
8a0f0fa70c65429b7515cd463481c21e99caa351 - MD5:
2ca1f5378899bb0dcb0a163768e3ec47 - ssdeep:
768:+gGzpDNp9Bp4B88on0p26puXVI4XqzXOZK+doExvU97znf:7GFZpalpu64XkOM4v27znf - TLSH:
T107316CF710A7ED8C7A8F6B47ADAB159D648AC28930369350449C372CD0BCAED3F10921 - Submitted as: visual_land_prestige_elite_9q_troubleshooting.pdf
- File type: pdf · Size: 42051 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=visual+land+prestige+elite+9q+troubleshooting, https://cdn.shopify.com/s/files/1/0266/8861/8677/files/72288307313.pdf, https://cdn.shopify.com/s/files/1/0498/1224/2586/files/campbell_urology_11th_edition_review.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=visual+land+prestige+elite+9q+troubleshooting
- https://cdn.shopify.com/s/files/1/0266/8861/8677/files/72288307313.pdf
- https://cdn.shopify.com/s/files/1/0498/1224/2586/files/campbell_urology_11th_edition_review.pdf
- https://cdn.shopify.com/s/files/1/0431/9327/0429/files/6187691296.pdf
- https://uploads.strikinglycdn.com/files/7e192df6-bffc-44d3-8abf-ebe0b67e3064/12011185612.pdf
- https://uploads.strikinglycdn.com/files/4b40c6d4-673b-4c70-ad0c-967b9bde820c/warhammer_warrior_priests.pdf
- https://s3.amazonaws.com/felasorarabipis/fujobutepeb.pdf
- https://s3.amazonaws.com/xanebavifamopez/winebuxoselokoxum.pdf
- https://s3.amazonaws.com/wilugugo/24280951963.pdf
- https://s3.amazonaws.com/susopuzupure/99445221757.pdf
- https://uploads.strikinglycdn.com/files/f728c5fb-d981-42de-aed1-a3e309714003/36030456947.pdf
- https://uploads.strikinglycdn.com/files/8fb4a909-427e-48f5-8b6f-d1257bb2fd50/gevisixani.pdf
- https://uploads.strikinglycdn.com/files/b41a7d83-ded6-44a3-82b5-35c126face8c/sanotonu.pdf
- https://uploads.strikinglycdn.com/files/b305d45e-16a5-4b83-9fbc-1b565275d04b/wuwabenakeku.pdf
- https://uploads.strikinglycdn.com/files/62c7b1f7-86ac-475a-bf37-ac84b587fe14/komoxivogaridixuzusoz.pdf
- https://cdn-cms.f-static.net/uploads/4379839/normal_5f8c2b208dfd4.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f873a5f7a929.pdf
- https://cdn-cms.f-static.net/uploads/4370294/normal_5f8bc00025b62.pdf
- https://cdn-cms.f-static.net/uploads/4375203/normal_5f8acfe2050cb.pdf
- https://uploads.strikinglycdn.com/files/bf4291b8-0416-47dd-97a7-cad577061bb3/femuj.pdf
- https://uploads.strikinglycdn.com/files/bc0999fe-421d-4f71-9cfc-cd963f39c248/12531700599.pdf
- https://uploads.strikinglycdn.com/files/be10446e-c962-4767-8583-698dc8ae8b9c/gibofazoxexusifibo.pdf
- https://uploads.strikinglycdn.com/files/564e0533-ef08-4064-9755-99a7fbf9824a/79887830140.pdf
- https://uploads.strikinglycdn.com/files/47a2d98f-93f3-44bd-a35c-ae42dd80b0d1/kaxutufudefovafolakulav.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- 1u.ly
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report