SUSPICIOUS — 16093055438.pdf
SUSPICIOUS — 16093055438.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1f82e4c3cca87fe416f25e97d1d4eda803158b32f90db8a5e55ddcb6621b8ee3 - SHA-1:
28fcc690083f3c4e51fa16fa4e5258ea95cf8d0a - MD5:
6d5d41de256b1a090f83a11820b7f0cf - ssdeep:
768:YgGzpDezUw3lVrVZ2KLmsTa7u3Jv70zSoRz4HX/T0:1GFKMKLHTJv70zSSz4HPT0 - TLSH:
T1472F8DF361A7EE8C398BAB435EA6155C508AD788B132976848CC376CC4FC27D6F10561 - Submitted as: 16093055438.pdf
- File type: pdf · Size: 35253 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=algebra+2+textbook+prentice+hall+pdf, https://uploads.strikinglycdn.com/files/3b5baa6e-ebc5-4496-becc-eeb80b80f2d3/gamezux.pdf, https://uploads.strikinglycdn.com/files/b3d8d013-2489-4191-93e4-489437a43a6a/13326883527.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=algebra+2+textbook+prentice+hall+pdf
- https://uploads.strikinglycdn.com/files/3b5baa6e-ebc5-4496-becc-eeb80b80f2d3/gamezux.pdf
- https://uploads.strikinglycdn.com/files/b3d8d013-2489-4191-93e4-489437a43a6a/13326883527.pdf
- https://uploads.strikinglycdn.com/files/be7681e6-8515-460e-9c14-450dae13103e/vovugovigufexobigekal.pdf
- https://uploads.strikinglycdn.com/files/4243296e-2c99-4bfc-b5d8-3a7d3b049e9f/23217982519.pdf
- https://uploads.strikinglycdn.com/files/29e3b682-4d37-4bee-8739-d81238d72a80/37057606639.pdf
- https://uploads.strikinglycdn.com/files/3ae360ac-cf87-42e1-ad94-edfc40c1f5b1/pipokewifaxivonixag.pdf
- https://uploads.strikinglycdn.com/files/f755fbc4-abf0-4546-b8b8-af754ef1ae55/somalakezin.pdf
- http://files.thoughtfullyseeking.com/uploads/1/3/0/7/130775970/mowexe_mabutejupe.pdf
- http://files.radhakripayoga.com/uploads/1/3/0/7/130776183/f2f505d.pdf
- http://sezuzelog.walnutstreetjuniorschool.com/uploads/1/3/0/7/130775990/noniraxope.pdf
- http://files.decoitowoods.com/uploads/1/3/0/7/130740589/5121108.pdf
- https://cdn.shopify.com/s/files/1/0434/3581/9173/files/blackpink_playing_with_fire_piano_sheet_easy.pdf
- https://cdn.shopify.com/s/files/1/0429/4914/8838/files/86185614853.pdf
- https://cdn.shopify.com/s/files/1/0438/5511/8501/files/60161441056.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.thoughtfullyseeking.com
- files.radhakripayoga.com
- sezuzelog.walnutstreetjuniorschool.com
- files.decoitowoods.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report