SUSPICIOUS — batomafanumig.pdf
SUSPICIOUS — batomafanumig.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
dd5af4c46bb7c6601bee7e873806b0c0dc1995f50e0cd38a8f398a9217a6de7d - SHA-1:
69c05ee2655babb4599f2f93ef41c3dae647c5df - MD5:
741f0404132055def238a3d74e720c0a - ssdeep:
768:fgGzpDkjJZf/4fOd+UYQ47PjPiGrt+BGReiFUMeoc/1am1oSCz7Mo:oGFQ3iHpw3ZH/mz7Mo - TLSH:
T114329EF710A7EC8C7B8A9B07ADE71199644AD74D6036872005CC772DE4BC6FD2E00962 - Submitted as: batomafanumig.pdf
- File type: pdf · Size: 45534 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=reading+and+writing+module+pdf, http://files.speechcoachmargo.com/uploads/1/3/1/1/131164402/325529e.pdf, http://files.minagcapital.com/uploads/1/3/1/3/131378952/d33ac7c4d850003.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=reading+and+writing+module+pdf
- http://files.speechcoachmargo.com/uploads/1/3/1/1/131164402/325529e.pdf
- http://files.minagcapital.com/uploads/1/3/1/3/131378952/d33ac7c4d850003.pdf
- http://files.familytreemandvbaker.com/uploads/1/3/0/7/130775286/9364227.pdf
- http://popofeke.katrinalehman.com/uploads/1/3/0/8/130873791/pitafe.pdf
- http://rerileja.organicfanatic.com.au/uploads/1/3/1/3/131380942/mitelagudin.pdf
- https://uploads.strikinglycdn.com/files/fd9ac299-3fdc-449d-8b4c-ee3467f1705d/4789883078.pdf
- https://uploads.strikinglycdn.com/files/d40d09c9-acc1-4bcf-b314-3035a0928b28/27243421036.pdf
- https://uploads.strikinglycdn.com/files/6fc15733-9715-4d91-93df-65783faebe96/nuputudotawara.pdf
- https://uploads.strikinglycdn.com/files/84dad2bf-0b32-4648-85d4-7b7f6f106e06/97486655672.pdf
- https://cdn.shopify.com/s/files/1/0496/1773/1735/files/candy_store_jordan_mn.pdf
- https://cdn.shopify.com/s/files/1/0434/4099/6518/files/implied_lines_in_art_define.pdf
- https://cdn.shopify.com/s/files/1/0457/6821/2646/files/linking_verb_practice_games.pdf
- https://cdn.shopify.com/s/files/1/0437/9626/7168/files/jumanji_welcome_to_the_jungle_watch_online_reddit.pdf
- https://cdn.shopify.com/s/files/1/0484/2949/8522/files/xoxalopo.pdf
- https://cdn.shopify.com/s/files/1/0484/1370/4349/files/dekisopewimivujo.pdf
- https://cdn.shopify.com/s/files/1/0481/2246/2371/files/libros_de_superacin_personal.pdf
- https://cdn.shopify.com/s/files/1/0430/4112/8601/files/what_does_curse_of_binding_do_on_a_trident.pdf
- https://cdn.shopify.com/s/files/1/0484/0721/6280/files/ck_science_crystal_growing_kit.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- files.speechcoachmargo.com
- files.minagcapital.com
- files.familytreemandvbaker.com
- popofeke.katrinalehman.com
- rerileja.organicfanatic.com.au
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report