SUSPICIOUS — the_fosters_season_guide.pdf
SUSPICIOUS — the_fosters_season_guide.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
31df0624f92be460e98f395c7cec59cb47ea80fdd0fe02e88229dc793608b9b6 - SHA-1:
e7eeb35bc8d8793506fc159e94d3ee325169426d - MD5:
00d60fb842c595a7722e034cfa882f5f - ssdeep:
768:5gGzpDMpnuBiphaN2xRL16Pyj+74e5nQd4TkIh+b9wqnOdyYnsX6afKuQHLtAgna:6GFIpnu7296sk4eu4Tt+h3OdyYsKafgQ - TLSH:
T1CD319EF3509BED8C3ACADB03ADA6106D9049C6496122DB30559C763DC8FCBBD6E109A0 - Submitted as: the_fosters_season_guide.pdf
- File type: pdf · Size: 43162 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=the+fosters+season+guide, https://uploads.strikinglycdn.com/files/a5acbde7-c271-49aa-9cd5-f0e48731669f/66330769020.pdf, https://uploads.strikinglycdn.com/files/6a595674-f636-49d7-a4c5-71ddb5d76e7d/85697033070.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=the+fosters+season+guide
- https://uploads.strikinglycdn.com/files/a5acbde7-c271-49aa-9cd5-f0e48731669f/66330769020.pdf
- https://uploads.strikinglycdn.com/files/6a595674-f636-49d7-a4c5-71ddb5d76e7d/85697033070.pdf
- https://uploads.strikinglycdn.com/files/949cbb3f-0f9a-4509-a2d3-c6758b312ce8/louis_vuitton_shoes_size_chart_in_cm.pdf
- https://uploads.strikinglycdn.com/files/3102a355-e815-47ee-82a8-1d2f74289ea2/30517081190.pdf
- https://uploads.strikinglycdn.com/files/3142983b-62e5-42e8-9c76-2fe5ffe09292/17103763248.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/6026554.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/7343677.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/gozesimoruwawe.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/kezupukono.pdf
- https://nejalebemenogun.weebly.com/uploads/1/3/1/0/131070187/rivuruxolaxukaz.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf
- https://rutaluxunenore.weebly.com/uploads/1/3/0/7/130740368/2424171.pdf
- https://cdn.shopify.com/s/files/1/0430/7877/9047/files/98688107602.pdf
- https://cdn.shopify.com/s/files/1/0486/6424/8470/files/honeywell_water_heater_thermostat_instructions.pdf
- https://uploads.strikinglycdn.com/files/5c7fb2cd-5969-4ed7-a21b-8151b34312fc/86523642722.pdf
- https://uploads.strikinglycdn.com/files/e1cfcd83-6b39-4223-b381-ef3396a5aa50/20272979226.pdf
- https://uploads.strikinglycdn.com/files/b7a7aa41-f368-4ad6-a419-4f82b87bee18/40329425871.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- zimiduninu.weebly.com
- xawuwotogot.weebly.com
- xebikazogede.weebly.com
- bedizegoresupa.weebly.com
- nejalebemenogun.weebly.com
- dutitujazekap.weebly.com
- rutaluxunenore.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report