SUSPICIOUS — bus_grease_monkey_youtube.pdf
SUSPICIOUS — bus_grease_monkey_youtube.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e91517c38b37dd0c1a68e9dbf515e1ba8abbd9283393962f6b8c30df416d9285 - SHA-1:
ee17524f14528e0be52104e2feb87ce7a63ff967 - MD5:
6042972a97a6bed73b3f424a625f908a - ssdeep:
768:OJgGzpD8eC0mjMpuBpMJhA60cQGyu4oYAfpM+kTAKpmrPb6laWdCVWQWyQ:nGFoejCdGyu9YAfi++AKpm7nWdgnWyQ - TLSH:
T1B5337DF35097ED8C7ACF6F07A9B7016D644AD3496137A7904888776CD0BC5EE2E00A51 - Submitted as: bus_grease_monkey_youtube.pdf
- File type: pdf · Size: 49897 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=bus+grease+monkey+youtube, https://cdn-cms.f-static.net/uploads/4366976/normal_5f910fdab8364.pdf, https://cdn-cms.f-static.net/uploads/4384482/normal_5f90ed83e74d7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=bus+grease+monkey+youtube
- https://cdn-cms.f-static.net/uploads/4366976/normal_5f910fdab8364.pdf
- https://cdn-cms.f-static.net/uploads/4384482/normal_5f90ed83e74d7.pdf
- https://cdn-cms.f-static.net/uploads/4368222/normal_5f91b91045180.pdf
- https://cdn-cms.f-static.net/uploads/4375518/normal_5f8b821cef624.pdf
- https://s3.amazonaws.com/mejigavukolu/caracteristicas_de_la_familia_asteraceae.pdf
- https://s3.amazonaws.com/jinabom/analisis_de_factibilidad_y_arboles_de_decision.pdf
- https://s3.amazonaws.com/subud/panasonic_ag-_ux180_user_manual.pdf
- https://s3.amazonaws.com/susopuzupure/nezag.pdf
- https://s3.amazonaws.com/memul/epf_non_employment_certificate.pdf
- https://s3.amazonaws.com/bevekizadoxuj/bss_ar133.pdf
- https://s3.amazonaws.com/wovitiku/sorting_algorithms_cheat_sheet.pdf
- https://uploads.strikinglycdn.com/files/73b264e0-a074-4c16-b164-699d7e02f6b0/88806449895.pdf
- https://uploads.strikinglycdn.com/files/08cf2bb5-21e6-4a94-a00e-af43903556b2/distribucion_de_probabilidad_discreta_ejercicios_resueltos.pdf
- https://uploads.strikinglycdn.com/files/5a08fc42-bcc1-4bdb-b360-d958cb942b34/mini_torch_lighter.pdf
- https://uploads.strikinglycdn.com/files/076795a4-8929-4cfd-baeb-dd0fed1012f4/94595310232.pdf
- https://uploads.strikinglycdn.com/files/5b3caa09-94a4-488c-8a7d-8057c734b9cc/talonro_geffenia_farming_guide.pdf
- https://uploads.strikinglycdn.com/files/246f15f2-0e0e-4824-baa2-74fdc03ba1c0/bukafarozajasovil.pdf
- https://uploads.strikinglycdn.com/files/256610d6-2022-4aea-9a50-ecc1b9b7b36f/labasemupopevenoj.pdf
- https://uploads.strikinglycdn.com/files/0c8cd891-f077-404b-b6f1-228815fe914c/lg_29fs4rl_service_manual.pdf
- https://uploads.strikinglycdn.com/files/b2375499-ede9-4437-92dd-de6cd5ba2e0f/5475771098.pdf
- https://uploads.strikinglycdn.com/files/2320bd6d-5b25-4b1f-97be-8f88f57a4dd3/xilelitewerupezesulap.pdf
- https://cdn-cms.f-static.net/uploads/4369150/normal_5f8a51ecd196c.pdf
- https://cdn-cms.f-static.net/uploads/4372972/normal_5f95fd8bc63dc.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f8a0d8f06af6.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report