SUSPICIOUS — 82542085097.pdf
SUSPICIOUS — 82542085097.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
5c56d9a0b98383279a7cb38e0ab3ae1627a8b6988639739f04a1d95994fd0a3d - SHA-1:
1300810337536febc91e10dcdf4c96b709b618cb - MD5:
160762f9779bffb5f891fd273a61bd62 - ssdeep:
768:MCgGzpDep959CWgjj/ki7GcDe2MwEV8vqK0CAXc4fPHXIuDpfp99jCmy9HiQZ/zg:KGFypFCLkk4fPHXIepR94z9Hf/zJu - TLSH:
T1E534AFF300EBED8C7A4B5B13AEB71059654ED7896033A720458C772CD4BCAAE7E10A11 - Submitted as: 82542085097.pdf
- File type: pdf · Size: 53291 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=you+may+ask+yourself+an+introduction+to+thinking+like+a+sociologist+fifth+edition+dalton+conley, https://cdn.shopify.com/s/files/1/0492/8225/2957/files/8816733896.pdf, https://cdn.shopify.com/s/files/1/0438/1225/7952/files/36915653771.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=you+may+ask+yourself+an+introduction+to+thinking+like+a+sociologist+fifth+edition+dalton+conley
- https://cdn.shopify.com/s/files/1/0492/8225/2957/files/8816733896.pdf
- https://cdn.shopify.com/s/files/1/0438/1225/7952/files/36915653771.pdf
- https://cdn.shopify.com/s/files/1/0497/2006/6209/files/twitch_trivia_download_apk.pdf
- https://cdn.shopify.com/s/files/1/0500/3444/2390/files/27795966091.pdf
- https://uploads.strikinglycdn.com/files/2cf44178-86d6-4689-8166-52b425734cb5/12801853491.pdf
- https://uploads.strikinglycdn.com/files/b7d32893-da09-4218-8a09-327d72f53e2b/wulodexamanabalukukime.pdf
- https://uploads.strikinglycdn.com/files/0c965be2-b0d5-4e3c-a9dd-961d7558bebe/69639612298.pdf
- https://cdn.shopify.com/s/files/1/0435/6685/8408/files/pejijajofugufizitozusi.pdf
- https://cdn.shopify.com/s/files/1/0433/6546/6266/files/meek_mill_bike_life_hacked.pdf
- https://cdn.shopify.com/s/files/1/0481/8046/1717/files/how_to_100_rest_in_peace_afk_arena.pdf
- https://cdn.shopify.com/s/files/1/0484/0121/9752/files/8510469493.pdf
- https://cdn.shopify.com/s/files/1/0437/9050/0001/files/tinajowudewujupel.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/kasawo-rakereroboxit-wuzunirib-midagawatebogef.pdf
- https://zuwumepegowivos.weebly.com/uploads/1/3/1/0/131069935/vetuwexirara.pdf
- https://lozulijulejibog.weebly.com/uploads/1/3/1/8/131857057/jodexavaligure.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/zikarab.pdf
- https://tekegalesi.weebly.com/uploads/1/3/0/7/130740489/4d869f1c.pdf
- https://temazojirilezin.weebly.com/uploads/1/3/2/3/132302863/47447b1e13d6.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/dowixipadutume.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f88c8f952888.pdf
- https://cdn-cms.f-static.net/uploads/4370278/normal_5f8bbce99e844.pdf
- https://cdn-cms.f-static.net/uploads/4368486/normal_5f8a1a4ea7049.pdf
- https://cdn-cms.f-static.net/uploads/4378406/normal_5f8aaf7ce7d3e.pdf
- https://cdn-cms.f-static.net/uploads/4373992/normal_5f88ec193f11d.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- jamuseramomuf.weebly.com
- zuwumepegowivos.weebly.com
- lozulijulejibog.weebly.com
- dutitujazekap.weebly.com
- tekegalesi.weebly.com
- temazojirilezin.weebly.com
- nobinetezo.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report