SUSPICIOUS — 93176393355.pdf
SUSPICIOUS — 93176393355.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a4783b55186eafaca6d46630c796ea8c1a93bb9a7948d8a804ae5556315ea98a - SHA-1:
da60a3b0841276be0d6157a1f16f2bb46372223f - MD5:
f39b9b02dda7a4d41e12e01792b0dc97 - ssdeep:
768:zgGzpD1anrP/V1D7ZTLSAGJVyI55CVn8SvbGPBKlj8MJ9jRrn:MGF5qTD7ZTLcJVPbCVnFvbGPBgjjjRrn - TLSH:
T168337CF3549BEC8C7ACB9B139C7A25216089D74CA237DB606498673DC0BC5BDBE10960 - Submitted as: 93176393355.pdf
- File type: pdf · Size: 47902 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=akers+hall+msu, https://uploads.strikinglycdn.com/files/fd55158f-126a-4197-b346-dcaca31ba602/wovokekiruv.pdf, https://uploads.strikinglycdn.com/files/7fe9de68-8b1a-4833-9c44-be61ade04993/18234636375.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=akers+hall+msu
- https://s3.amazonaws.com/subud/71335556567.pdf
- https://s3.amazonaws.com/tigovatolis/myanmar_grade_9_english_textbook.pdf
- https://s3.amazonaws.com/metubevozisul/alternity_2017.pdf
- https://s3.amazonaws.com/dazemi/zizopis.pdf
- https://uploads.strikinglycdn.com/files/fd55158f-126a-4197-b346-dcaca31ba602/wovokekiruv.pdf
- https://uploads.strikinglycdn.com/files/7fe9de68-8b1a-4833-9c44-be61ade04993/18234636375.pdf
- https://uploads.strikinglycdn.com/files/5edd7a13-6b27-4af9-9f3a-f8ca6f041ff3/lugamabinafe.pdf
- https://uploads.strikinglycdn.com/files/d29afe21-bfe5-4db5-a8b2-033cf29707bf/36426905984.pdf
- https://pevinuwipe.weebly.com/uploads/1/3/0/8/130873962/6952638.pdf
- https://talowitutujuf.weebly.com/uploads/1/3/3/9/133999148/mezetefawogoz_lesux_wivolo.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/3029889.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/9ba64029b4.pdf
- https://s3.amazonaws.com/guxosa/71100564941.pdf
- https://s3.amazonaws.com/xanebavifamopez/tovufobilixeref.pdf
- https://s3.amazonaws.com/vuraradaso/building_construction_technology_notes.pdf
- https://s3.amazonaws.com/fovezewi/beninca_lady_barrier.pdf
- https://s3.amazonaws.com/sulasatevirexo/bugazeleme.pdf
- https://s3.amazonaws.com/vonuxagupeduze/genudiwobaxoseli.pdf
- https://s3.amazonaws.com/tojabixefova/cairo_city_map.pdf
- https://s3.amazonaws.com/subud/understanding_blockchain_technology.pdf
- https://s3.amazonaws.com/felasorarabipis/84855411737.pdf
- https://s3.amazonaws.com/henghuili-files2/bekogasopuna.pdf
- https://s3.amazonaws.com/felasorarabipis/pazevuzinuvovaseva.pdf
- https://s3.amazonaws.com/paxivogedewilu/brca1_y_brca2_cancer_de_mama.pdf
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- pevinuwipe.weebly.com
- talowitutujuf.weebly.com
- jakedekokobara.weebly.com
- pevugubak.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report