SUSPICIOUS — music_rhythm_games_unblocked.pdf
SUSPICIOUS — music_rhythm_games_unblocked.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
98b0413b65cad4c61b68f6de47b527b77ecce53daa5b757a6e310f0341a7eb4e - SHA-1:
2e94142635178e1ca9fabc3fd60192ffff509810 - MD5:
918f36312deae67178b54bea984c2301 - ssdeep:
768:jgGzpDUHtgfGrS5BXlKvW93eIz1+/krg9afh:cGF4NCmSbXlaW93eIUL9afh - TLSH:
T1D7307DF31197DD8CBA86A7039EEB15481145C3496233ABA058DC772CC4BC6FD7E51AA0 - Submitted as: music_rhythm_games_unblocked.pdf
- File type: pdf · Size: 36161 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/pify?keyword=music+rhythm+games+unblocked, https://uploads.strikinglycdn.com/files/70c09aac-5caa-4093-a66b-153f7b789e65/5243553657.pdf, https://uploads.strikinglycdn.com/files/66c368b7-86bf-4160-a9e3-207cb7f93884/sududaxejuvoroj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/pify?keyword=music+rhythm+games+unblocked
- https://uploads.strikinglycdn.com/files/70c09aac-5caa-4093-a66b-153f7b789e65/5243553657.pdf
- https://uploads.strikinglycdn.com/files/66c368b7-86bf-4160-a9e3-207cb7f93884/sududaxejuvoroj.pdf
- https://uploads.strikinglycdn.com/files/f0d5091d-ad23-4d2d-9b06-af9e340f649c/jomor.pdf
- https://uploads.strikinglycdn.com/files/27f6f08e-a99a-4071-b059-d23f026e8eee/vinisazonoj.pdf
- https://site-1039513.mozfiles.com/files/1039513/63344568033.pdf
- https://site-1041845.mozfiles.com/files/1041845/47152669198.pdf
- https://site-1042548.mozfiles.com/files/1042548/71348125770.pdf
- https://site-1037169.mozfiles.com/files/1037169/91436472519.pdf
- https://site-1042625.mozfiles.com/files/1042625/zesivivefebibirija.pdf
- https://uploads.strikinglycdn.com/files/3b25bab8-b38e-4da0-8bce-4c8c5d8fba32/66423276998.pdf
- https://uploads.strikinglycdn.com/files/4198ee19-8775-4bd8-ba6c-3e5096721f52/48333575152.pdf
- https://uploads.strikinglycdn.com/files/512d51ef-6549-400a-960d-f40c4b7bbe19/sefimawexa.pdf
- https://uploads.strikinglycdn.com/files/70b97f40-6b3e-4189-b6f4-77da3fd03058/mowowumekamagopezijoxose.pdf
- https://site-1039180.mozfiles.com/files/1039180/kalujawulupe.pdf
- https://site-1037240.mozfiles.com/files/1037240/91439928411.pdf
- https://site-1042107.mozfiles.com/files/1042107/lowurono.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- uploads.strikinglycdn.com
- site-1039513.mozfiles.com
- site-1041845.mozfiles.com
- site-1042548.mozfiles.com
- site-1037169.mozfiles.com
- site-1042625.mozfiles.com
- site-1039180.mozfiles.com
- site-1037240.mozfiles.com
- site-1042107.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report