SUSPICIOUS — can_t_stop_praising_his_name_chords.pdf
SUSPICIOUS — can_t_stop_praising_his_name_chords.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
9fb70e12be25c6bc9a86cb3d29616ccb66796c7030c28f5193a9f2616e4338e3 - SHA-1:
87b9222a920b262456395e8174da342f7ee2e627 - MD5:
a59af99711d80126c072c5138117b3aa - ssdeep:
768:ZgGzpD+pZ4jp8EK0GoZS4Wb9ww7rqShNlcQpt4hXlY52/bNAwasDsR1u:aGFSpi60Gx4Ql4VhNtLg3u - TLSH:
T168329EF35077ED4C7A4B9B537EEA114D9149C7882032ABA545887B2CC4BC6BD3F01A61 - Submitted as: can_t_stop_praising_his_name_chords.pdf
- File type: pdf · Size: 45500 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=can+t+stop+praising+his+name+chords, https://uploads.strikinglycdn.com/files/746fe2e5-4aa0-4f05-9bf0-1ab986462319/26108237943.pdf, https://uploads.strikinglycdn.com/files/bd5128a5-52f5-4dcb-8f8f-69bf20bfb295/92687636532.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=can+t+stop+praising+his+name+chords
- https://uploads.strikinglycdn.com/files/746fe2e5-4aa0-4f05-9bf0-1ab986462319/26108237943.pdf
- https://uploads.strikinglycdn.com/files/bd5128a5-52f5-4dcb-8f8f-69bf20bfb295/92687636532.pdf
- https://uploads.strikinglycdn.com/files/db6de591-ba2a-43a0-b235-75186e9a95d4/escuela_humano_relacionista.pdf
- https://uploads.strikinglycdn.com/files/53c24bbd-90bd-4e7d-80c5-327e176bb1ab/77179680381.pdf
- https://uploads.strikinglycdn.com/files/4238fbe7-4143-4db5-af6d-f3a64a581976/depogom.pdf
- https://uploads.strikinglycdn.com/files/2e76d27e-985d-4499-a638-208d733d4c88/rexukij.pdf
- https://cdn.shopify.com/s/files/1/0483/9515/7662/files/2188722109.pdf
- https://cdn.shopify.com/s/files/1/0481/5100/3303/files/tosonokurikuweravidadat.pdf
- https://cdn-cms.f-static.net/uploads/4377391/normal_5f89cb28354c4.pdf
- https://cdn-cms.f-static.net/uploads/4369923/normal_5f89672c0ac5a.pdf
- https://cdn-cms.f-static.net/uploads/4370543/normal_5f886dbe0241d.pdf
- https://cdn.shopify.com/s/files/1/0486/0893/6096/files/nbde_score_report.pdf
- https://cdn.shopify.com/s/files/1/0479/0114/7302/files/difiore_atlas_of_histology.pdf
- https://cdn.shopify.com/s/files/1/0501/0201/0021/files/how_to_add_a_running_header_in_google_docs.pdf
- https://cdn.shopify.com/s/files/1/0437/9436/6626/files/pelofuv.pdf
- https://cdn.shopify.com/s/files/1/0476/4460/6630/files/xoratotoludajinikezebadip.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report