SUSPICIOUS — wavelength_to_wavenumber_converter.pdf
SUSPICIOUS — wavelength_to_wavenumber_converter.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
70b256e0c358de42625ff32de68cc812d51b141f28508cf71defd113f856c18e - SHA-1:
2bcd4bf92a6b140ab18c55181d10d83e2cafb89f - MD5:
ea2731173c9531478aea62a4574218e4 - ssdeep:
768:K8gGzpDyyUj7SwZdSVjESiY+b+WvgPCXYfiVL/tX60RT/A8XawIZIJKX2J:KZGFeioSVgtYaoWVVL/J60RjnjIZIkGJ - TLSH:
T18E329EF3506BDC8C268A9B03AEAA145C7145D78D713396A004C9777CC4BCAFD7E10A62 - Submitted as: wavelength_to_wavenumber_converter.pdf
- File type: pdf · Size: 45396 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=wavelength+to+wavenumber+converter, https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/1387600.pdf, https://silepokow.weebly.com/uploads/1/3/4/3/134366863/mebimukeforulikem.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=wavelength+to+wavenumber+converter
- https://s3.amazonaws.com/bofake/aws_certification_dumps_free_download.pdf
- https://s3.amazonaws.com/henghuili-files2/21504494152.pdf
- https://s3.amazonaws.com/zetare/jurukinakajojuwivides.pdf
- https://s3.amazonaws.com/subud/topinugeruwil.pdf
- https://s3.amazonaws.com/vibuvomomuv/carcinoma_de_celulas_escamosas_en_animales.pdf
- https://s3.amazonaws.com/sakaburepagase/all_english_spelling_rules.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/1387600.pdf
- https://silepokow.weebly.com/uploads/1/3/4/3/134366863/mebimukeforulikem.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/monirafulowafix.pdf
- https://s3.amazonaws.com/rufonali/how_to_interpret_descriptive_statistics_in_spss.pdf
- https://s3.amazonaws.com/rebomedug/65764171650.pdf
- https://cdn-cms.f-static.net/uploads/4384030/normal_5f8f5b1b7905b.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f872db168eb9.pdf
- https://cdn-cms.f-static.net/uploads/4366655/normal_5f8b0f8a714ef.pdf
- https://s3.amazonaws.com/mejados/geliseropepolurijojitede.pdf
- https://s3.amazonaws.com/jasadavebaga/amelie_piano_sheet_music_comptine.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- dejolezeg.weebly.com
- silepokow.weebly.com
- gimejexoxixaza.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report