SUSPICIOUS — normal_5f874a1856c28.pdf
SUSPICIOUS — normal_5f874a1856c28.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1fa20b51b8955f044861b9074df2625e66adfb4829a0a82b54d84674a0798cc2 - SHA-1:
5a952bea908f74cae044e831950cef2481c354d0 - MD5:
d2506dd5dc7b77b92e99b99fadb28068 - ssdeep:
768:cKgGzpDypHFlKAX1sZeABFuX7azUZNn5RXmB2I9frABGdXwE+ChGRV8jfnpSW7UW:6GFupzWHWXMUZMAHChG78r4z6cmqg - TLSH:
T10B328EF32067ED4CB78F9B07ADAB2199644AD7886132979014C83A1CC5BCAFD7F50521 - Submitted as: normal_5f874a1856c28.pdf
- File type: pdf · Size: 46658 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=pokemon+go+beta+game+download+for+android, https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/1f2f042291555f9.pdf, https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/penodiw-tiregolugu-vafas.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=pokemon+go+beta+game+download+for+android
- https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/1f2f042291555f9.pdf
- https://pevugubak.weebly.com/uploads/1/3/2/7/132740457/penodiw-tiregolugu-vafas.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/zuvefusu_tewojawowebav.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/kezedivalo-bolumukejufufik.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/5401885.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f8724db36d9d.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f6548e65e.pdf
- https://site-1039815.mozfiles.com/files/1039815/29986290203.pdf
- https://site-1039674.mozfiles.com/files/1039674/nuwuximelukutafotave.pdf
- https://site-1043352.mozfiles.com/files/1043352/zatigenunobudaz.pdf
- https://site-1036633.mozfiles.com/files/1036633/73855724211.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f872f84877f7.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f870301c253b.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f87093ea5831.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f873a109d4a3.pdf
- https://cdn.shopify.com/s/files/1/0436/3816/1561/files/talent_show_contest_rules.pdf
- https://cdn.shopify.com/s/files/1/0500/2500/5206/files/1666474708.pdf
- https://cdn.shopify.com/s/files/1/0436/3649/0398/files/7076402853.pdf
- https://cdn.shopify.com/s/files/1/0479/4459/7671/files/watch_blade_runner_2049_full_movie_online_free_streaming.pdf
- https://cdn.shopify.com/s/files/1/0484/3012/1112/files/35130951872.pdf
- https://cdn.shopify.com/s/files/1/0463/8353/0139/files/99349027340.pdf
- https://cdn.shopify.com/s/files/1/0432/2174/5823/files/sivatikirisoluregufipoki.pdf
- https://cdn.shopify.com/s/files/1/0481/4412/2009/files/65311721979.pdf
- https://cdn.shopify.com/s/files/1/0431/2730/8454/files/detroit_lakes_high_school_staff.pdf
Embedded domains
- gettraff.ru
- gemaxudemaxepeb.weebly.com
- pevugubak.weebly.com
- jawasolasazilem.weebly.com
- dimaxafazeza.weebly.com
- mogilifus.weebly.com
- cdn-cms.f-static.net
- site-1039815.mozfiles.com
- site-1039674.mozfiles.com
- site-1043352.mozfiles.com
- site-1036633.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report