SUSPICIOUS — normal_5f87b56160d3a.pdf
SUSPICIOUS — normal_5f87b56160d3a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
036c86ede36f9fe3564ac3e35c0dd5ee50ce06c1bbeec433bc3579b2b8559f5a - SHA-1:
5fc392b0ebb51e4797b8260804fc9e216b31caaa - MD5:
4e5d93853f4f6bda4d0caf8c8ddca211 - ssdeep:
768:ngGzpDEpAMtbKjA5FclJDRf98QbOaQ02n5IVwrhrUMcitEWBh53mdx0ilkVCJQRl:gGFgp5KjA5CRfd8ANk0AS9fRw - TLSH:
T11E34BFF35077EC8D7A8FAF83BCE6115AB599C1C99023AA9058CC265CD4686FD3F10981 - Submitted as: normal_5f87b56160d3a.pdf
- File type: pdf · Size: 54210 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=imsi+catcher+detector+apk, https://cdn.shopify.com/s/files/1/0437/1503/5288/files/ramaw.pdf, https://cdn.shopify.com/s/files/1/0429/3269/9302/files/the_legend_of_zelda_wallpaper_phone.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=imsi+catcher+detector+apk
- https://cdn.shopify.com/s/files/1/0437/1503/5288/files/ramaw.pdf
- https://cdn.shopify.com/s/files/1/0429/3269/9302/files/the_legend_of_zelda_wallpaper_phone.pdf
- https://cdn.shopify.com/s/files/1/0484/6852/5210/files/roaming_captains_nessus.pdf
- https://cdn.shopify.com/s/files/1/0434/0498/4474/files/dujotutinage.pdf
- https://cdn.shopify.com/s/files/1/0500/9250/7301/files/lord_of_the_flies_teaching_guide.pdf
- https://cdn.shopify.com/s/files/1/0484/0420/1624/files/95936169696.pdf
- https://cdn.shopify.com/s/files/1/0484/0488/9760/files/zapebanedulugader.pdf
- https://cdn.shopify.com/s/files/1/0432/4658/3970/files/download_android_for_iphone_6.pdf
- https://cdn.shopify.com/s/files/1/0481/2347/8179/files/jalonodagiwuxizo.pdf
- https://cdn.shopify.com/s/files/1/0268/7673/9764/files/55885549326.pdf
- https://cdn.shopify.com/s/files/1/0432/2036/9567/files/solving_one_step_equations_with_algebra_tiles_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0498/0693/4178/files/west_albany_high_school.pdf
- https://cdn.shopify.com/s/files/1/0497/1954/1921/files/penn_state_library_university_park.pdf
- https://cdn.shopify.com/s/files/1/0440/8098/8310/files/bokunoxekofijosem.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f877893c0355.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f870983d360d.pdf
- https://cdn-cms.f-static.net/uploads/4368248/normal_5f876e40d23fd.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f8719e74da85.pdf
- https://cdn.shopify.com/s/files/1/0481/4055/0311/files/xebobagosaxo.pdf
- https://cdn.shopify.com/s/files/1/0435/1436/4059/files/wuwumojoz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report