SUSPICIOUS — normal_5f88d38d302f0.pdf
SUSPICIOUS — normal_5f88d38d302f0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
002e18230cc56d9dab7d10de067fc4abec87e1504625166a725d4a5d54ae495a - SHA-1:
8ecea24a87d39dca56b29bf91a3b7290a3f876f7 - MD5:
877dc02421794786d959912087edd060 - ssdeep:
768:JgGzpDlpjRA4HFSgm9SnLbpaVE3xloiVZuWGbrrZ5cGPPJrdr:qGFZpyQR6E3xloQZDon4GPPJrdr - TLSH:
T16E319DF35097ED8C7D8BAB136EA71258618AD34CB1328B6045CC7B6DD4BC6BC6E40960 - Submitted as: normal_5f88d38d302f0.pdf
- File type: pdf · Size: 41920 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=taiwan+travel+guide+pdf+download, https://site-1044010.mozfiles.com/files/1044010/farm_forestry_in_pakistan.pdf, https://site-1042188.mozfiles.com/files/1042188/70048697600.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=taiwan+travel+guide+pdf+download
- https://site-1044010.mozfiles.com/files/1044010/farm_forestry_in_pakistan.pdf
- https://site-1042188.mozfiles.com/files/1042188/70048697600.pdf
- https://site-1048530.mozfiles.com/files/1048530/tratamiento_para_verrugas_planas.pdf
- https://mamunazeve.weebly.com/uploads/1/3/0/8/130814121/volupubaxenidiwos.pdf
- https://zulatikuwa.weebly.com/uploads/1/3/0/7/130776211/4094919.pdf
- https://cdn-cms.f-static.net/uploads/4368492/normal_5f87c462db494.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f870e1b3d754.pdf
- https://site-1042442.mozfiles.com/files/1042442/85792097223.pdf
- https://site-1042355.mozfiles.com/files/1042355/91437223776.pdf
- https://uploads.strikinglycdn.com/files/0e307759-ddb0-4891-a834-ef00d3960084/31914913010.pdf
- https://uploads.strikinglycdn.com/files/e47ea1e9-23df-46c5-a2ee-fa1893726d54/vibaguxuzetefiraluz.pdf
- https://uploads.strikinglycdn.com/files/9caab686-34ad-4539-ac92-a1c9f78324fe/fujugidosopaledibu.pdf
- https://uploads.strikinglycdn.com/files/62620b5a-8873-4e9c-aaf8-a1528adc8180/65719032616.pdf
- https://uploads.strikinglycdn.com/files/bb16dbbb-663b-4059-aad9-a4e6d6272b00/vazisirexiraropu.pdf
- https://uploads.strikinglycdn.com/files/694ffc96-62fb-449d-afb6-c91935bc404e/fewazidulavurasimolol.pdf
- https://uploads.strikinglycdn.com/files/91b917ce-90ff-4f35-b374-cd39e21b10e7/91671958189.pdf
- https://uploads.strikinglycdn.com/files/eba99fa6-cb0c-4b83-bdd3-06ea845f6414/18693546286.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1044010.mozfiles.com
- site-1042188.mozfiles.com
- site-1048530.mozfiles.com
- mamunazeve.weebly.com
- zulatikuwa.weebly.com
- cdn-cms.f-static.net
- site-1042442.mozfiles.com
- site-1042355.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report