SUSPICIOUS — can_you_tame_alphas.pdf
SUSPICIOUS — can_you_tame_alphas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
6b9ae633d5863150254e5418d4e244bad415b9aeedfb075103556a4bf590ea48 - SHA-1:
5eb5f3499fca3943533048c9618c008483e18bd9 - MD5:
6d270871e65f65f4a8a732efb5666b50 - ssdeep:
768:3gGzpDbpiKKcddT7F0hmG61ZFGVoobqlOgzAbbfU33j/gTnV1K7YOHI:QGF3pCxOIbUnrgTsYOHI - TLSH:
T150328DF350A7ED8C3A8BAF03ADBB056D648ED78C613297904498276CC47C6ED2F10A55 - Submitted as: can_you_tame_alphas.pdf
- File type: pdf · Size: 45418 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=can+you+tame+alphas, https://cdn-cms.f-static.net/uploads/4365628/normal_5f874b26f0bb2.pdf, https://cdn-cms.f-static.net/uploads/4368953/normal_5f886b8b17477.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=can+you+tame+alphas
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f874b26f0bb2.pdf
- https://cdn-cms.f-static.net/uploads/4368953/normal_5f886b8b17477.pdf
- https://cdn-cms.f-static.net/uploads/4368474/normal_5f87db79d2845.pdf
- https://cdn-cms.f-static.net/uploads/4368762/normal_5f88a7602f1b5.pdf
- https://uploads.strikinglycdn.com/files/4ff60cb1-9a8e-4f57-b1d2-695d1e03ce65/43608178302.pdf
- https://uploads.strikinglycdn.com/files/31a4ef6b-7411-4774-9b0d-eb54f6f3351e/83235484012.pdf
- https://uploads.strikinglycdn.com/files/90d4930e-64ad-493c-bd32-5015dda5840f/ropasosipujoxuxadonifeve.pdf
- https://uploads.strikinglycdn.com/files/fb02342d-0a8c-46dc-9f7f-6db344ca9b17/47421865075.pdf
- https://uploads.strikinglycdn.com/files/19ed3b19-5e94-4fc6-88d3-dcaa1ef689cc/vibus.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/7059380717.pdf
- https://cdn.shopify.com/s/files/1/0483/1497/4363/files/punctuation_saves_lives_poster.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xereromejiv-koxozirusoror-moxonujis.pdf
- https://xifobosakup.weebly.com/uploads/1/3/2/8/132815359/totewojet.pdf
- https://pivozedotafi.weebly.com/uploads/1/3/1/0/131070355/2147291.pdf
- https://mapipuluzobeb.weebly.com/uploads/1/3/1/3/131398440/pebudo_tataz_busezefalikir.pdf
- https://lowizozexide.weebly.com/uploads/1/3/0/7/130776176/78b9ce93e284b45.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f86f5d59d3e4.pdf
- https://cdn-cms.f-static.net/uploads/4382643/normal_5f8b63d99b1ca.pdf
- https://cdn-cms.f-static.net/uploads/4369183/normal_5f8920571918a.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f8b5ef784934.pdf
- https://cdn.shopify.com/s/files/1/0434/5587/3190/files/45060455011.pdf
- https://cdn.shopify.com/s/files/1/0434/0957/1990/files/gabosomofozevulubarukenaz.pdf
- https://cdn.shopify.com/s/files/1/0428/4396/3548/files/windows_live_movie_maker_apk.pdf
- https://cdn.shopify.com/s/files/1/0484/3490/5240/files/fundamentals_of_automobile_body_structure_design.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- dutitujazekap.weebly.com
- xifobosakup.weebly.com
- pivozedotafi.weebly.com
- mapipuluzobeb.weebly.com
- lowizozexide.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report