SUSPICIOUS — foundations_of_parasitology_8th_edition.pdf
SUSPICIOUS — foundations_of_parasitology_8th_edition.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
03012873368fba78335acd1d34efffc8a753f54b40da2f6d65f5030e5a9c4480 - SHA-1:
c8930ff60f22eb703d68d09747da7578cf6adb2b - MD5:
342f695ef34e9cc87d63b935fc0b0430 - ssdeep:
768:dvgGzpDjpwrzJqBC/2c+Dz2qjhGQOItapmgfl6vRuuWcjMZr4snV:mGFPpwJQ9tapB96vRZNQZ0SV - TLSH:
T189318DF310A7ED4C7A8B9F43AEA7129E714AC68C7132879054C8762CD1B85ED7F10960 - Submitted as: foundations_of_parasitology_8th_edition.pdf
- File type: pdf · Size: 42840 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=foundations+of+parasitology+8th+edition+pdf, https://cdn.shopify.com/s/files/1/0488/4080/2469/files/wifuviniroz.pdf, https://cdn.shopify.com/s/files/1/0437/3705/5393/files/19558137925.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=foundations+of+parasitology+8th+edition+pdf
- https://cdn.shopify.com/s/files/1/0488/4080/2469/files/wifuviniroz.pdf
- https://cdn.shopify.com/s/files/1/0437/3705/5393/files/19558137925.pdf
- https://cdn.shopify.com/s/files/1/0433/9541/6213/files/wise_onion_rings_near_me.pdf
- https://cdn.shopify.com/s/files/1/0478/1791/6575/files/future_progressive_tense_exercises_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0435/3795/7023/files/international_thespian_society_logo.pdf
- https://zoxetojasag.weebly.com/uploads/1/3/1/4/131437223/nadasor.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/xovejaxikufu_kosev.pdf
- https://juzugimigiroteg.weebly.com/uploads/1/3/2/3/132302883/mivevoluni.pdf
- https://wojeribexojuxu.weebly.com/uploads/1/3/1/8/131856158/4099773.pdf
- https://sisodiwitamusoz.weebly.com/uploads/1/3/2/6/132681746/2868229.pdf
- https://cdn.shopify.com/s/files/1/0439/5322/5883/files/vivaluditewazanamepumugep.pdf
- https://cdn.shopify.com/s/files/1/0439/1731/2152/files/linejisej.pdf
- https://lefedatit.weebly.com/uploads/1/3/0/7/130776734/putedesatamuba.pdf
- https://fidegobopoj.weebly.com/uploads/1/3/2/8/132815019/59181733d4337.pdf
- https://mujunoba.weebly.com/uploads/1/3/2/6/132682006/857194.pdf
- https://koxoganonigowup.weebly.com/uploads/1/3/1/4/131408343/6176058.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/4102594.pdf
- https://cdn-cms.f-static.net/uploads/4369933/normal_5f8ca9b52a584.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f875ee309349.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f87f9d9270c6.pdf
- https://uploads.strikinglycdn.com/files/edec7767-1595-49b7-b09f-f5bbdb77faa0/29393387006.pdf
- https://uploads.strikinglycdn.com/files/907a3c08-bf59-454d-bf83-eeb4b3cad620/46566312016.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- zoxetojasag.weebly.com
- babikovinemixe.weebly.com
- juzugimigiroteg.weebly.com
- wojeribexojuxu.weebly.com
- sisodiwitamusoz.weebly.com
- lefedatit.weebly.com
- fidegobopoj.weebly.com
- mujunoba.weebly.com
- koxoganonigowup.weebly.com
- mogilifus.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report