SUSPICIOUS — prison_break_subtitles_season_4.pdf
SUSPICIOUS — prison_break_subtitles_season_4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8fb189728fa7ba63fd7511ad336673ecf02ef2b6350c4dabf64c1096b8d53e71 - SHA-1:
6a221cf5da3056ecb86ea58de7b877e91a634364 - MD5:
d4e0a2a9fd3abcacd53d56c965b74e1e - ssdeep:
768:jgGzpD7fvkzXiCMLsLvTrhHvZ2R8H1h7GE7Ofij9hcBGZt:cGF3fOhvR1h7Go7hcBGZt - TLSH:
T1D1307DF350A3EC8C3B8A6F13AABB1199558AD74930739A6054DC372CD4BC7ED2E10961 - Submitted as: prison_break_subtitles_season_4.pdf
- File type: pdf · Size: 36179 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=prison+break+subtitles+season+4, https://uploads.strikinglycdn.com/files/ebc24ee0-8e19-465b-9168-23a66067fae5/nusuvaxisod.pdf, https://uploads.strikinglycdn.com/files/97142168-cbee-44f1-bdff-5b7712353e6a/56230072443.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=prison+break+subtitles+season+4
- https://uploads.strikinglycdn.com/files/ebc24ee0-8e19-465b-9168-23a66067fae5/nusuvaxisod.pdf
- https://uploads.strikinglycdn.com/files/97142168-cbee-44f1-bdff-5b7712353e6a/56230072443.pdf
- https://uploads.strikinglycdn.com/files/d68bb78a-02de-4601-b719-84aaa82dd268/wumenis.pdf
- https://uploads.strikinglycdn.com/files/5fd1ec03-95a4-4fd5-bf72-f02aae7ba5b3/77877419364.pdf
- https://uploads.strikinglycdn.com/files/6699b9ad-d11a-4ee6-b164-13d4a9449bdd/do_you_change_your_apple_id.pdf
- https://baletepo.weebly.com/uploads/1/3/0/7/130776023/pimanu-gafoxalami-tetawotenejalu.pdf
- https://uploads.strikinglycdn.com/files/10392893-14ff-4ce1-92e5-5dba53f8199c/xonugakeragokuguzejego.pdf
- https://uploads.strikinglycdn.com/files/dc4aad39-b280-4f11-928e-cd0338f8ce2d/80228926635.pdf
- https://uploads.strikinglycdn.com/files/db68f7e3-8c76-41ea-a878-200862dd0cc0/karibesubiw.pdf
- https://cdn.shopify.com/s/files/1/0436/3550/7358/files/pugudebisivegufapo.pdf
- https://cdn.shopify.com/s/files/1/0482/2551/7720/files/transformation_process_in_the_production_of_goods_and_services.pdf
- https://cdn.shopify.com/s/files/1/0483/3434/0259/files/50946639453.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/98322281891.pdf
- https://cdn.shopify.com/s/files/1/0437/3318/8762/files/anonymous_browsing_app_android.pdf
- https://uploads.strikinglycdn.com/files/984572df-af23-4a48-a0c7-037f4593225e/86066782964.pdf
- https://uploads.strikinglycdn.com/files/6404db2c-580c-4f0a-acfa-b90d75da1b85/31211734022.pdf
- https://uploads.strikinglycdn.com/files/6b3babc7-c358-4ac0-b53e-2f0a9ff9ef67/10686598263.pdf
- https://uploads.strikinglycdn.com/files/9b3fbe92-a313-471b-9714-86522697b793/50194184533.pdf
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f92435b441a7.pdf
- https://cdn-cms.f-static.net/uploads/4369306/normal_5f8cb30f86d1a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- baletepo.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report