SUSPICIOUS — 20289620106.pdf
SUSPICIOUS — 20289620106.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c7947c70485aa6f09a449b5103e99d4f9492595f03e8e77f1da191cbc7bceb16 - SHA-1:
3040e1b0ccfb3a0cc322d7c0da53f1a5efb454d7 - MD5:
d8835b580e0c0061d3dc1cdf184f4525 - ssdeep:
768:0gGzpD1dgJ7M314v24o87NfUyifDWQSl1f2mOXJYzr5kE6ZMh/WvOy86EqAYFJNA:BGFpWRum1fr7neE6ZSWvcyjlJ5dQ - TLSH:
T196329EF3109BEC4C3A8A9F23A9A6106AA48ED74D203696A0459C777CD0BC5FD7D01A91 - Submitted as: 20289620106.pdf
- File type: pdf · Size: 44372 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=nba+stream+subreddit, https://uploads.strikinglycdn.com/files/01f771a1-97b6-4d39-9503-b7fbfa0d63c8/79399461108.pdf, https://uploads.strikinglycdn.com/files/4752adcd-1210-4245-ac05-293713cd6221/71895961703.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=nba+stream+subreddit
- https://uploads.strikinglycdn.com/files/01f771a1-97b6-4d39-9503-b7fbfa0d63c8/79399461108.pdf
- https://uploads.strikinglycdn.com/files/4752adcd-1210-4245-ac05-293713cd6221/71895961703.pdf
- https://uploads.strikinglycdn.com/files/35ca8c4b-7501-43f5-adc6-c35aaf92e210/koleg.pdf
- https://uploads.strikinglycdn.com/files/0f853d63-a708-4d0d-83fe-4b2458fc401d/gudufuberagomusaguk.pdf
- https://cdn.shopify.com/s/files/1/0435/0243/6512/files/46225631671.pdf
- https://cdn.shopify.com/s/files/1/0429/4970/5881/files/ruxaxurave.pdf
- https://cdn.shopify.com/s/files/1/0480/8956/3299/files/sodomy_in_the_bible.pdf
- https://cdn.shopify.com/s/files/1/0434/0645/9032/files/boluro.pdf
- https://cdn.shopify.com/s/files/1/0441/1303/5416/files/2015_ap_chemistry_free_response.pdf
- https://cdn.shopify.com/s/files/1/0434/9090/2166/files/tatenodewulinikitesofofos.pdf
- https://cdn.shopify.com/s/files/1/0437/6828/3287/files/fallout_4_sim_settlements_industrial_upgrade_requirements.pdf
- https://cdn.shopify.com/s/files/1/0437/5986/1912/files/green_beauty_guide.pdf
- https://cdn.shopify.com/s/files/1/0429/9502/4025/files/ecocolumns_ap_environmental_science.pdf
- https://cdn.shopify.com/s/files/1/0434/3395/1399/files/46383278436.pdf
- https://cdn.shopify.com/s/files/1/0483/9365/0325/files/40889926719.pdf
- https://cdn.shopify.com/s/files/1/0483/1671/1076/files/72911259807.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report