SUSPICIOUS — normal_5f8a0203c118c.pdf
SUSPICIOUS — normal_5f8a0203c118c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0cfd9264d320b10c8e3dfd584e8cddf48b35da88627ed5e7ebad6d0b5fc5de3a - SHA-1:
da3a55ec913067b14f92cfe75a9925f669760a00 - MD5:
db161f4202e2c26221f9da686f941127 - ssdeep:
768:MgGzpDZesabPXFlDfEazDhpz1siXO7vkaOQQVFO0Ptk7moNrkzOlMHUOiY:JGFNeb31si+bkaOQ8FH3hzOSHUOiY - TLSH:
T14432AEF35067DD8C7A87AB136AF62018510AD74D7272A7A158DC3B2CC4BC3AC7E11660 - Submitted as: normal_5f8a0203c118c.pdf
- File type: pdf · Size: 45351 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=voter+list+delhi+with+photo+pdf, https://uploads.strikinglycdn.com/files/993f0230-90d0-4127-ba11-e75f27f6e5c1/68214095326.pdf, https://uploads.strikinglycdn.com/files/8a6b072c-faf3-4da1-81cb-5e3fdc03166a/25530040509.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=voter+list+delhi+with+photo+pdf
- https://uploads.strikinglycdn.com/files/993f0230-90d0-4127-ba11-e75f27f6e5c1/68214095326.pdf
- https://uploads.strikinglycdn.com/files/8a6b072c-faf3-4da1-81cb-5e3fdc03166a/25530040509.pdf
- https://uploads.strikinglycdn.com/files/7db9b6a2-38f7-4ec8-ab67-33d7f0c1306d/zusaxosabeboraxelefepav.pdf
- https://cdn-cms.f-static.net/uploads/4368479/normal_5f87ad74ea1f5.pdf
- https://cdn.shopify.com/s/files/1/0479/5993/3095/files/the_deepest_well_free.pdf
- https://cdn.shopify.com/s/files/1/0482/1237/7754/files/pimetumitikob.pdf
- https://uploads.strikinglycdn.com/files/95247db7-12d5-4b6f-8663-9b5aed26079a/74103862072.pdf
- https://uploads.strikinglycdn.com/files/684acc6e-ebf8-44ac-adbc-b021e0689ea6/rifuba.pdf
- https://uploads.strikinglycdn.com/files/abdd75ff-9c8d-4867-a6bc-c3df24006cb2/92724190317.pdf
- https://uploads.strikinglycdn.com/files/52a69267-e5d5-424c-a6b1-baf75bba6260/10015947824.pdf
- https://cdn.shopify.com/s/files/1/0266/8750/4583/files/vinurabekewujefozasosif.pdf
- https://cdn.shopify.com/s/files/1/0495/9682/5764/files/how_to_draw_a_soccer_goalie_glove.pdf
- https://cdn.shopify.com/s/files/1/0499/9276/1494/files/61238092560.pdf
- https://cdn-cms.f-static.net/uploads/4367273/normal_5f8747004e584.pdf
- https://cdn-cms.f-static.net/uploads/4366628/normal_5f874e44528fe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report