SUSPICIOUS — 40894223663.pdf
SUSPICIOUS — 40894223663.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ae545ec0bea29ea0581838f954076c0b5245ef19a0c9861070b48c963bed410b - SHA-1:
f669bfd2cc95fb9a84bad94d588439081f116fe3 - MD5:
f880c2957b0d7856ce2de12b18b6fa42 - ssdeep:
1536:zGFWGHADjk2Iz70MrnyuQL1RK1SDjUd/I:CFWGsjk2Iz7CuQLPp8C - TLSH:
T11D34AEF31067EC4C6A8A67036EA611AE9149DB4CB173AB6105DC372CC0BC6FE7E40965 - Submitted as: 40894223663.pdf
- File type: pdf · Size: 53557 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=soviet+airland+battle+tactics+pdf, https://cdn.shopify.com/s/files/1/0434/3840/7845/files/tatawabapuxuxabajobisewi.pdf, https://cdn.shopify.com/s/files/1/0434/3375/4780/files/bigo_apk_ios.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=soviet+airland+battle+tactics+pdf
- https://cdn.shopify.com/s/files/1/0434/3840/7845/files/tatawabapuxuxabajobisewi.pdf
- https://cdn.shopify.com/s/files/1/0434/3375/4780/files/bigo_apk_ios.pdf
- https://cdn.shopify.com/s/files/1/0432/4923/8179/files/22252833409.pdf
- https://cdn.shopify.com/s/files/1/0482/7273/6411/files/94562235402.pdf
- https://cdn.shopify.com/s/files/1/0437/5887/8881/files/descriptive_inorganic_chemistry_6th_edition.pdf
- http://laravulaz.elitetaxadvisory.com.au/uploads/1/3/0/8/130874455/7100049.pdf
- http://pakubu.cbcky.net/uploads/1/3/1/6/131636698/wivata-vufemeson-madofivoxivoxig-mikudidu.pdf
- http://files.jj-figurines.com/uploads/1/3/1/1/131163777/999a4.pdf
- http://vupubi.pnwcleaner.com/uploads/1/3/0/7/130739416/surosolinizopubiweku.pdf
- http://vikabezo.ashleyssweetchips.com/uploads/1/3/2/6/132695663/rolumukukowevosute.pdf
- https://cdn.shopify.com/s/files/1/0496/0518/1603/files/96209979856.pdf
- https://cdn.shopify.com/s/files/1/0428/6673/7311/files/6283243898.pdf
- https://cdn.shopify.com/s/files/1/0497/2471/9261/files/unidad_4_leccion_1_reteaching_and_practice_page_9.pdf
- https://cdn.shopify.com/s/files/1/0482/7591/4913/files/tongva_hills_gta_5_location.pdf
- https://cdn.shopify.com/s/files/1/0485/0060/5089/files/bunojajop.pdf
- https://cdn.shopify.com/s/files/1/0466/2591/5045/files/5031944060.pdf
- https://cdn.shopify.com/s/files/1/0482/2053/6989/files/psychsim_5_expressing_emotion_bfw.pdf
- https://cdn.shopify.com/s/files/1/0496/7527/2349/files/zanakubemibexasurun.pdf
- https://cdn.shopify.com/s/files/1/0434/6576/9113/files/59441319411.pdf
- https://cdn.shopify.com/s/files/1/0431/8062/1984/files/dekoselisopebeto.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- laravulaz.elitetaxadvisory.com.au
- pakubu.cbcky.net
- files.jj-figurines.com
- vupubi.pnwcleaner.com
- vikabezo.ashleyssweetchips.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report