SUSPICIOUS — domain_driven_design_ebook.pdf
SUSPICIOUS — domain_driven_design_ebook.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
cd49a35c8eba23270c2e719fc9e709d98579c932e62ee70bcc1ab02ae613c962 - SHA-1:
5eff879f02e1e3817a33ae71d38c1ff9d90ee4d3 - MD5:
ae7ac721568a99fbf39e578cf94a9144 - ssdeep:
768:qgGzpDZpPGcfYBqfcq4voHzBcHiWKk96+unDipqCTCj3oNCqwd+HqZN:3GFFpucAyfzEbk+unOpxCj1UHqZN - TLSH:
T15B328CF310A7FD9C768BAB475EA2155A648DC38C613287A0448C777CC57C6FD6E00A61 - Submitted as: domain_driven_design_ebook.pdf
- File type: pdf · Size: 47046 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=domain+driven+design+ebook, https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/e87da8.pdf, https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/2122744.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=domain+driven+design+ebook
- https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/e87da8.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/2122744.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/54d21.pdf
- https://cdn.shopify.com/s/files/1/0427/9628/6119/files/farm_town_cache.pdf
- https://cdn.shopify.com/s/files/1/0433/0700/8168/files/sibema.pdf
- https://cdn.shopify.com/s/files/1/0436/6296/6937/files/55903038379.pdf
- https://uploads.strikinglycdn.com/files/ae8d9ccf-4056-4393-aba2-8cbbe8905b8a/21612941711.pdf
- https://uploads.strikinglycdn.com/files/866fd850-de67-4bb1-922e-a3ef8d2dce72/rabojogivoxawukixigatan.pdf
- https://uploads.strikinglycdn.com/files/af72041c-de58-4ba4-b165-473177149502/lujabijewunelewusa.pdf
- https://uploads.strikinglycdn.com/files/1a3f2ff4-2044-4cba-b2d5-a63366fd6093/dadiboliferuposunipivagem.pdf
- https://uploads.strikinglycdn.com/files/974e238b-1f82-443a-b40f-11a6250ed609/20837308332.pdf
- https://goduvozimaku.weebly.com/uploads/1/3/1/3/131380582/4770499.pdf
- https://rewemekekebaz.weebly.com/uploads/1/3/1/4/131406535/6578987.pdf
- https://naroxelilokatud.weebly.com/uploads/1/3/1/3/131384214/6186fc42adc4.pdf
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/nugifavaseminilise.pdf
- https://nasinapalu.weebly.com/uploads/1/3/0/7/130739684/2011601.pdf
- https://cdn-cms.f-static.net/uploads/4367302/normal_5f875e2c17c74.pdf
- https://cdn-cms.f-static.net/uploads/4366358/normal_5f873ca1c4980.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- vixijusodu.weebly.com
- xojerajap.weebly.com
- natizupasa.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- goduvozimaku.weebly.com
- rewemekekebaz.weebly.com
- naroxelilokatud.weebly.com
- xazapadikud.weebly.com
- nasinapalu.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report