SUSPICIOUS — monsieur_ibrahim_et_les_fleurs_du_co.pdf
SUSPICIOUS — monsieur_ibrahim_et_les_fleurs_du_co.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
03d8769a2dd74f7def367815879f01a150b2fe9138b1a503af590f7f63388fca - SHA-1:
2b7580b985ea9e023ab31503961360bf12471b92 - MD5:
84a5fee446775440ede41619ad861aee - ssdeep:
1536:lGFLM429tSwNWELopfjWDQbykE/Wg8znvQtS:4FLM429gwNWdpfjWEW7uvL - TLSH:
T131359FF301B7ED8C76CB9F43B9A70059604AD68C313296A045D8B76CC5BCABE6F10A51 - Submitted as: monsieur_ibrahim_et_les_fleurs_du_co.pdf
- File type: pdf · Size: 57906 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=monsieur+ibrahim+et+les+fleurs+du+co, https://uploads.strikinglycdn.com/files/b44ccba4-ba8d-4960-8092-a9a9346e8c52/86690017892.pdf, https://uploads.strikinglycdn.com/files/d2bf2154-928a-4e40-be53-98c9b2121640/bulut.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=monsieur+ibrahim+et+les+fleurs+du+co
- https://uploads.strikinglycdn.com/files/b44ccba4-ba8d-4960-8092-a9a9346e8c52/86690017892.pdf
- https://uploads.strikinglycdn.com/files/d2bf2154-928a-4e40-be53-98c9b2121640/bulut.pdf
- https://uploads.strikinglycdn.com/files/8a062458-566b-47fd-bdc1-c1767904ea8c/adobe_photoshop_ebook_free_download.pdf
- https://uploads.strikinglycdn.com/files/717d7f14-0f54-4f78-b058-37e62092a1e0/fenapijuzelanubifa.pdf
- https://cdn.shopify.com/s/files/1/0502/2557/8159/files/libro_de_ortopedia_infantil_rosselli.pdf
- https://cdn.shopify.com/s/files/1/0430/8677/4436/files/wetipom.pdf
- https://cdn.shopify.com/s/files/1/0501/9828/2420/files/92210240610.pdf
- https://cdn-cms.f-static.net/uploads/4366395/normal_5f8e1e7b4763f.pdf
- https://cdn-cms.f-static.net/uploads/4367019/normal_5f88a46586637.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f8e6df19f577.pdf
- https://buliduxefexefux.weebly.com/uploads/1/3/1/6/131636978/6938031.pdf
- https://finazodaxuvoj.weebly.com/uploads/1/3/2/6/132682535/4584344.pdf
- https://wegonugu.weebly.com/uploads/1/3/4/0/134040733/mugavowitedamexokugo.pdf
- https://tuxitusonodedin.weebly.com/uploads/1/3/0/8/130873989/ripatugefosola.pdf
- https://pudegubazamase.weebly.com/uploads/1/3/1/1/131163945/pifalowij.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/8644275.pdf
- https://cdn.shopify.com/s/files/1/0496/7117/6345/files/nukegaxewovadovomow.pdf
- https://cdn.shopify.com/s/files/1/0494/3288/7463/files/8494300345.pdf
- https://cdn.shopify.com/s/files/1/0483/2437/8787/files/limited_service_retailer.pdf
- https://cdn.shopify.com/s/files/1/0504/2746/1782/files/68543960995.pdf
- https://cdn.shopify.com/s/files/1/0462/9918/5312/files/paleo_meal_plan_for_weight_loss.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- buliduxefexefux.weebly.com
- finazodaxuvoj.weebly.com
- wegonugu.weebly.com
- tuxitusonodedin.weebly.com
- pudegubazamase.weebly.com
- kabudededawizo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report