SUSPICIOUS — algebra_meme_gif.pdf
SUSPICIOUS — algebra_meme_gif.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
97d141b549e01eda61dc56c228174b3a2ffc1356bdbcefecc5865607205d3356 - SHA-1:
007e752bbaf266c004fc00b82fdc2bf24807f169 - MD5:
af95254ac354831acf5fc2a9778c5f59 - ssdeep:
768:qgGzpDkygfNWN4OxyUjDKQ4vLYPuTxG7c8fUn+0e8oPmMGXW/RKGrsKdJ5F0:3GFoIN4OxyUjD2e8ouMz/RK4f5F0 - TLSH:
T14D338DF321E3ED4C7B8AAB036DE611A9518ACB4C6133A761448C672CE5BC5FE7E10950 - Submitted as: algebra_meme_gif.pdf
- File type: pdf · Size: 48187 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=algebra+meme+gif, https://cdn-cms.f-static.net/uploads/4392463/normal_5f99097c9d964.pdf, https://cdn.shopify.com/s/files/1/0429/5960/1830/files/26182066573.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=algebra+meme+gif
- https://cdn-cms.f-static.net/uploads/4392463/normal_5f99097c9d964.pdf
- https://cdn.shopify.com/s/files/1/0429/5960/1830/files/26182066573.pdf
- https://uploads.strikinglycdn.com/files/47ab3d2c-90b6-4945-8685-33d0d0eff138/56373814409.pdf
- https://cdn.shopify.com/s/files/1/0481/7751/2597/files/86133320273.pdf
- https://fidegobopoj.weebly.com/uploads/1/3/2/8/132815019/4dec071a34d11.pdf
- https://meporolokiso.weebly.com/uploads/1/3/2/6/132681401/6408329.pdf
- https://cdn.shopify.com/s/files/1/0497/5480/0282/files/kesirixabibuxodovasez.pdf
- https://cdn.shopify.com/s/files/1/0435/0600/8216/files/google_super_mario_bros_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0497/3897/3345/files/iso_14001_training.pdf
- https://uploads.strikinglycdn.com/files/634b1a7e-b4d3-42c8-a7d1-3ffbdb25f484/kixifog.pdf
- https://uploads.strikinglycdn.com/files/19dd60cc-d35d-40e3-b780-88dc920c1570/vauxhall_omega_workshop_manual_free_download.pdf
- https://cdn-cms.f-static.net/uploads/4390097/normal_5f9349b36d929.pdf
- https://uploads.strikinglycdn.com/files/cddc5896-d866-4a24-81dd-8417983febf5/lerupi.pdf
- https://cdn.shopify.com/s/files/1/0429/5956/9055/files/kohl_center_seating_chart_view.pdf
- https://uploads.strikinglycdn.com/files/90c49b10-ddde-4ca2-9050-24a072b9e34f/mipapuwajoxazema.pdf
- https://cdn.shopify.com/s/files/1/0434/7186/3961/files/transformar_excel_em_online.pdf
- https://uploads.strikinglycdn.com/files/fd2dbb8b-6f6f-489e-81ed-4979f705e5cd/80128859141.pdf
- https://zavomafig.weebly.com/uploads/1/3/4/3/134356936/8222137.pdf
- https://cdn-cms.f-static.net/uploads/4402940/normal_5f96103772efc.pdf
- https://jirewolekaza.weebly.com/uploads/1/3/4/3/134387643/xolajabidokafamu.pdf
- https://cdn-cms.f-static.net/uploads/4380545/normal_5f9310922a456.pdf
- https://cdn.shopify.com/s/files/1/0492/4204/6630/files/tangle_free_brush_roll_vacuum.pdf
- https://uploads.strikinglycdn.com/files/c1085137-44fb-4ba2-9d13-1ca158e363bc/borat_1080p_castellano.pdf
- https://cdn.shopify.com/s/files/1/0503/4373/9560/files/88307202727.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- fidegobopoj.weebly.com
- meporolokiso.weebly.com
- zavomafig.weebly.com
- jirewolekaza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report