SUSPICIOUS — gun_mayhem_2_y8.pdf
SUSPICIOUS — gun_mayhem_2_y8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
703183627519a50893b2e1b73a6d827d47faa80787fff7b7a350d57f94fdda7c - SHA-1:
4386396ca12567e9a3160fadec6549d02f7db551 - MD5:
2a1d9901e5ee508a4f68a49f27fe6024 - ssdeep:
768:UgGzpDKpLXuzxIJD6NGrTzRkE164C3mmqeLrUlxNuyVDPZgp3psFg:hGFWpLKiULrAxhV7ZQpsFg - TLSH:
T1B5305CF350A3DD4C7A8BAF43ADA71198A04EC74D602797A01488772CD5BCBFE6E10A51 - Submitted as: gun_mayhem_2_y8.pdf
- File type: pdf · Size: 36531 bytes
- Verdict: suspicious (35/100)
Detections (3 of 50 engines)
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=gun+mayhem+2+y8, https://cdn-cms.f-static.net/uploads/4366007/normal_5f875a412abc2.pdf, https://cdn-cms.f-static.net/uploads/4366042/normal_5f872c433f08a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=gun+mayhem+2+y8
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f875a412abc2.pdf
- https://cdn-cms.f-static.net/uploads/4366042/normal_5f872c433f08a.pdf
- https://cdn-cms.f-static.net/uploads/4374852/normal_5f8dab25a0f1d.pdf
- https://cdn-cms.f-static.net/uploads/4377656/normal_5f8a0f05e4361.pdf
- https://cdn-cms.f-static.net/uploads/4381297/normal_5f8d337a154e3.pdf
- https://cdn-cms.f-static.net/uploads/4369802/normal_5f87febaee534.pdf
- https://cdn-cms.f-static.net/uploads/4372101/normal_5f88a0638cd69.pdf
- https://cdn-cms.f-static.net/uploads/4372361/normal_5f8c630a42a7e.pdf
- https://cdn-cms.f-static.net/uploads/4373259/normal_5f8c7afe214b1.pdf
- https://cdn-cms.f-static.net/uploads/4366309/normal_5f8726b286879.pdf
- https://cdn-cms.f-static.net/uploads/4378853/normal_5f8b6f587d96c.pdf
- https://cdn-cms.f-static.net/uploads/4369926/normal_5f8d05e0c07ee.pdf
- https://cdn-cms.f-static.net/uploads/4375716/normal_5f8d0b378c823.pdf
- https://cdn-cms.f-static.net/uploads/4369920/normal_5f8c848d3b949.pdf
- https://uploads.strikinglycdn.com/files/c282cb4f-0fee-4c39-986f-2bba345d1733/80518864311.pdf
- https://uploads.strikinglycdn.com/files/a8634fb8-17cc-42a6-a4e7-5ee5f037ead6/7200063205.pdf
- https://uploads.strikinglycdn.com/files/42d50597-5026-48c6-9c7b-a18886d967e3/997648662.pdf
- https://uploads.strikinglycdn.com/files/ad29bd8d-731d-4d78-860a-9f818d0c7839/77037794605.pdf
- https://uploads.strikinglycdn.com/files/2a663a79-4931-4742-a72b-c3f39bf20e7e/27818269787.pdf
- https://uploads.strikinglycdn.com/files/f512ce9f-3a0e-4904-8a20-c45b2169f6ed/fisiologia_humana_silverthorn_6ta_ed.pdf
- https://uploads.strikinglycdn.com/files/356a1115-bcc8-4204-b0c2-186ad9555f7b/86199075215.pdf
- https://uploads.strikinglycdn.com/files/0c7d9d17-7d50-40fb-967a-152adfe03064/favizajodetipugunasubar.pdf
- https://uploads.strikinglycdn.com/files/988f2e42-3781-4914-b33c-bca403f13c6f/19442239383.pdf
- https://uploads.strikinglycdn.com/files/9b160460-6d75-4f2a-98a6-3eccfbacd7e1/29569088419.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report