SUSPICIOUS — cyberpowerpc_gamer_supreme_liquid_cool_slc8280w.pdf
SUSPICIOUS — cyberpowerpc_gamer_supreme_liquid_cool_slc8280w.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8eefbcbff6f4317ce2d15ac69949efc9b58d4cfc4be5d311fdd8e954a8971b45 - SHA-1:
74daf97d391e9bac980ea87d85c5a6136543e03d - MD5:
41b5d7b8ef0bef680d3a46a7305ff76d - ssdeep:
768:ugGzpD/h38ajOI1AxXC4Ib36YxiR1jmSv+hmKyS7TzAQj:LGFbeajAxXCiR1Ks+hmKfAQj - TLSH:
T1C032AFF350A7DD8D6BC6EF07AEE61099654AC68C6132966014C87B7CD8B87FD6E00C21 - Submitted as: cyberpowerpc_gamer_supreme_liquid_cool_slc8280w.pdf
- File type: pdf · Size: 43616 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=cyberpowerpc+gamer+supreme+liquid+cool+slc8280w, https://fukikabigo.weebly.com/uploads/1/3/4/4/134457586/wagopovuji_zitupojefi_dafumepuguzoz_jobirinon.pdf, https://cdn.shopify.com/s/files/1/0500/1229/1264/files/datepicker_android_studio_java.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=cyberpowerpc+gamer+supreme+liquid+cool+slc8280w
- https://s3.amazonaws.com/susopuzupure/endoproteza_stawu_kolanowego_rehabilitacja.pdf
- https://fukikabigo.weebly.com/uploads/1/3/4/4/134457586/wagopovuji_zitupojefi_dafumepuguzoz_jobirinon.pdf
- https://cdn.shopify.com/s/files/1/0500/1229/1264/files/datepicker_android_studio_java.pdf
- https://s3.amazonaws.com/dutimajizowa/70265526236.pdf
- https://bufetokarad.weebly.com/uploads/1/3/4/0/134096279/33b5a24c8c5.pdf
- https://mogijoduvide.weebly.com/uploads/1/3/0/8/130814471/691b4f85991.pdf
- https://pepotoxuxomupav.weebly.com/uploads/1/3/1/4/131483830/tisiwatijew_zixilawoj_gowewoniloramu_jisokime.pdf
- https://cdn-cms.f-static.net/uploads/4384154/normal_5f8fff1d49c5d.pdf
- https://s3.amazonaws.com/nijosinizo/wawup.pdf
- https://cdn.shopify.com/s/files/1/0500/0524/6112/files/structures_endowments_and_institutions_in_the_economic_history_of_latin_america.pdf
- https://cdn.shopify.com/s/files/1/0504/0527/7894/files/possessive_pronouns_worksheets.pdf
- https://s3.amazonaws.com/bevekizadoxuj/gta_vice_city_cheats_pc_english.pdf
- https://s3.amazonaws.com/dalava/free_all_right_now_guitar_tab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- fukikabigo.weebly.com
- cdn.shopify.com
- bufetokarad.weebly.com
- mogijoduvide.weebly.com
- pepotoxuxomupav.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report