SUSPICIOUS — ejercicios_de_word_avanzado_2016.pdf
SUSPICIOUS — ejercicios_de_word_avanzado_2016.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
81a4fbfcd3fa0d544dd1b1f5a5d7d9ac1a0adb974c93be66d082ddf23a93d906 - SHA-1:
c167a4a396b8b82a381403a61e4f6268fbc017f4 - MD5:
1d96d9dd26963c76c4981ad0eb3ad881 - ssdeep:
768:44gGzpDQ5w/Zq7xmkwhh934vodBMVSxbuvgRh8P:CGF09FXA/MVY6vgRh8P - TLSH:
T108306BF310E3DC4C6A8BAB47A9B7154C654A838C61379760488C6B7DC4BCABD7F10A61 - Submitted as: ejercicios_de_word_avanzado_2016.pdf
- File type: pdf · Size: 36315 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=ejercicios+de+word+avanzado+2016, https://cdn.shopify.com/s/files/1/0501/3232/0451/files/tas_school_holidays_2020.pdf, https://cdn.shopify.com/s/files/1/0503/3879/1582/files/download_novel_wuthering_heights_bahasa_indonesia.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=ejercicios+de+word+avanzado+2016
- https://s3.amazonaws.com/pujinit/48925905030.pdf
- https://s3.amazonaws.com/pazifetanegapu/93767911111.pdf
- https://s3.amazonaws.com/tetazino/libosevututoloxoti.pdf
- https://cdn.shopify.com/s/files/1/0501/3232/0451/files/tas_school_holidays_2020.pdf
- https://cdn.shopify.com/s/files/1/0503/3879/1582/files/download_novel_wuthering_heights_bahasa_indonesia.pdf
- https://uploads.strikinglycdn.com/files/1b1c27e9-3442-4364-b288-e106a2a8ed16/vendor_due_diligence_report_example.pdf
- https://uploads.strikinglycdn.com/files/c0c63426-1bd8-47f4-afae-6b0a2f91dee8/pugevozexig.pdf
- https://uploads.strikinglycdn.com/files/e599c367-c80f-4080-8f91-85c87e1409fc/charlies_angel_streaming.pdf
- https://uploads.strikinglycdn.com/files/b3ebd30e-8509-44ec-b8ef-9d25fb746c51/xosovitujatasiwetatav.pdf
- https://uploads.strikinglycdn.com/files/20ac3ed5-df78-4df9-b21e-1b2b9c50e807/kiwiwotunodujadawisipara.pdf
- https://uploads.strikinglycdn.com/files/b87fb6d0-1503-49b6-93ae-65fe36e31866/53134713335.pdf
- https://uploads.strikinglycdn.com/files/b503acbb-9514-4c9e-ae4c-69ac4f212fa4/65317052062.pdf
- https://uploads.strikinglycdn.com/files/3a2417dd-8cc9-4679-b89f-30e0fc470326/24389007803.pdf
- https://uploads.strikinglycdn.com/files/3aecbe1d-c6cb-4ecd-9d4c-36ac4b4bf80b/se_anuncia_un_asesinato.pdf
- https://uploads.strikinglycdn.com/files/614f4516-4120-45f1-bfa0-ccf3754836a7/bexupimenugixuvefawes.pdf
- https://s3.amazonaws.com/penefelomiju/definition_of_social_media_by_different_authors.pdf
- https://s3.amazonaws.com/wixamupelinere/third_conditional_reading.pdf
- https://s3.amazonaws.com/gizonukorad/nasa_artemis_program.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report