SUSPICIOUS — normal_5f876a55c2f21.pdf
SUSPICIOUS — normal_5f876a55c2f21.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
00b4ee28342b0d09c9e8dabf970a9a6553f824376b2c091865a57736177dc36c - SHA-1:
cd90706b953779c4c5d5e42da81e2c741559cf48 - MD5:
b134db03f09f0d8824391c9994d3f1b9 - ssdeep:
768:kgGzpDSp5w7PeT7mKdxN60E5fdUFY27nsSPfKyAjubv31NtB+8tTMHAa9yJ+LJh:RGFWpdDP1+fdUFFsryvFXg8tLJ+LJh - TLSH:
T1FA328DF354ABDD4C7A879703B9A72469958AC38CA133A76044CC362CD5BC5BD7E20960 - Submitted as: normal_5f876a55c2f21.pdf
- File type: pdf · Size: 45190 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=bronislaw+malinowski+ksiazki+pdf, https://uploads.strikinglycdn.com/files/23d973d4-604e-4cce-852d-bc9e3b754e56/nugetuvakipesixofawonup.pdf, https://uploads.strikinglycdn.com/files/3c32175a-0eb5-41d2-adc3-7a9c006e3d9c/rufagavojijevebeka.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=bronislaw+malinowski+ksiazki+pdf
- https://uploads.strikinglycdn.com/files/23d973d4-604e-4cce-852d-bc9e3b754e56/nugetuvakipesixofawonup.pdf
- https://uploads.strikinglycdn.com/files/3c32175a-0eb5-41d2-adc3-7a9c006e3d9c/rufagavojijevebeka.pdf
- https://uploads.strikinglycdn.com/files/7f891510-e790-4181-aff3-e681d19302ce/52932550591.pdf
- https://site-1043938.mozfiles.com/files/1043938/14834825786.pdf
- https://site-1038815.mozfiles.com/files/1038815/12884579571.pdf
- https://site-1042983.mozfiles.com/files/1042983/pujawuku.pdf
- https://site-1040141.mozfiles.com/files/1040141/34523149534.pdf
- https://site-1042101.mozfiles.com/files/1042101/free_printable_preschool_valentines_day_worksheets.pdf
- https://cdn.shopify.com/s/files/1/0469/0205/0978/files/liberty_ridge_farm_sunflower_festival.pdf
- https://cdn.shopify.com/s/files/1/0481/3884/6371/files/basic_electrical_questions_and_answers_in_tamil.pdf
- https://cdn.shopify.com/s/files/1/0433/8896/0924/files/id_come_for_you_nickelback_letra.pdf
- https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/xolube.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/44d87feaf8ee.pdf
- https://dojulukasinu.weebly.com/uploads/1/3/0/7/130776790/pizinawi.pdf
- https://cdn-cms.f-static.net/uploads/4365636/normal_5f8757378d47c.pdf
- https://cdn-cms.f-static.net/uploads/4365553/normal_5f87157fb4681.pdf
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f8767ce8936b.pdf
- https://cdn-cms.f-static.net/uploads/4367304/normal_5f87672d2a289.pdf
- https://site-1043123.mozfiles.com/files/1043123/65738835169.pdf
- https://site-1043165.mozfiles.com/files/1043165/wekupibasejavegiduku.pdf
- https://site-1043760.mozfiles.com/files/1043760/26619834153.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1043938.mozfiles.com
- site-1038815.mozfiles.com
- site-1042983.mozfiles.com
- site-1040141.mozfiles.com
- site-1042101.mozfiles.com
- cdn.shopify.com
- wonigebegi.weebly.com
- mojivimimujovo.weebly.com
- dojulukasinu.weebly.com
- cdn-cms.f-static.net
- site-1043123.mozfiles.com
- site-1043165.mozfiles.com
- site-1043760.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report