SUSPICIOUS — normal_5f960770c9f88.pdf
SUSPICIOUS — normal_5f960770c9f88.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
206c008fbdaa3736a32db4f936633cb1539dbd82d7a56347623efcc51999246e - SHA-1:
f2ae425705c7f017b862b0bb13027a844f142f18 - MD5:
30e27d15df6f23b7b4290d958b807a1a - ssdeep:
1536:BGFteWW71tgJfew35sYpsxE2+p+pPjWc+WayIj1HKC7YF:kFteWy7gJmw35sY2SkPUhbZA - TLSH:
T13335AEF30097EC4D7ACAEF036EEB252D654AC7886233A7214488672CC5BCABD7D14561 - Submitted as: normal_5f960770c9f88.pdf
- File type: pdf · Size: 63048 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=artflow+paint+draw+sketchbook+apk, https://cdn.shopify.com/s/files/1/0479/6855/1068/files/squirrel_hill_cinema.pdf, https://cdn.shopify.com/s/files/1/0497/3897/3345/files/enerlites_het01-c_programmable_timer_switch_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=artflow+paint+draw+sketchbook+apk
- https://cdn.shopify.com/s/files/1/0479/6855/1068/files/squirrel_hill_cinema.pdf
- https://cdn.shopify.com/s/files/1/0497/3897/3345/files/enerlites_het01-c_programmable_timer_switch_manual.pdf
- https://cdn.shopify.com/s/files/1/0268/7673/9764/files/sheep_illnesses_uk.pdf
- https://cdn.shopify.com/s/files/1/0432/5251/4979/files/derozinewizi.pdf
- https://cdn.shopify.com/s/files/1/0428/9737/5388/files/free_download_spotify_premium_apk_for_pc.pdf
- https://uploads.strikinglycdn.com/files/93be3f9f-92e7-4f90-9cb8-9d6fe0002cf3/bowurinesopus.pdf
- https://uploads.strikinglycdn.com/files/ce11aca9-46a8-4abf-962d-229b76df605c/how_to_download_skyrim_se_creation_k.pdf
- https://uploads.strikinglycdn.com/files/1e31334f-cdae-48dc-9cc0-829ab7e15fa7/pewewijaruvixetimebi.pdf
- https://uploads.strikinglycdn.com/files/3d03aa47-8522-420d-8d15-dea7f27c6248/motojemimubigan.pdf
- https://uploads.strikinglycdn.com/files/63476992-de43-48a4-a72b-06abfd19a94d/94145723971.pdf
- https://cdn.shopify.com/s/files/1/0488/2844/8933/files/4865634529.pdf
- https://cdn.shopify.com/s/files/1/0432/5025/3984/files/56051858660.pdf
- https://cdn.shopify.com/s/files/1/0499/8588/0214/files/writing_idiomatic_python_3.3_free_download.pdf
- https://cdn.shopify.com/s/files/1/0502/2393/9753/files/gmail_android_app_message_queued.pdf
- https://cdn.shopify.com/s/files/1/0427/3651/7286/files/67886174997.pdf
- https://cdn.shopify.com/s/files/1/0496/5960/9245/files/gediwavotaxusabiv.pdf
- https://cdn.shopify.com/s/files/1/0434/2536/6165/files/animal_description_worksheets.pdf
- https://uploads.strikinglycdn.com/files/7675bdde-ea76-46e5-ac60-be43a19a43a2/zodobixijovenasikedipin.pdf
- https://uploads.strikinglycdn.com/files/2be1c753-a513-4eab-a35a-6f4eca07accc/19040854709.pdf
- https://uploads.strikinglycdn.com/files/a54a511c-87c8-4867-8bd3-cc78d8560426/chinese_letter.pdf
- https://uploads.strikinglycdn.com/files/280ffcbc-ed15-4ad4-9b46-6855f3365ab3/yanmar_1610d_owners_manual.pdf
- https://tumixivig.weebly.com/uploads/1/3/1/6/131636813/galudi.pdf
- https://babinekisifuve.weebly.com/uploads/1/3/2/6/132696104/razipusiw_damonanazike_teludakofebi.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/rusisikojaruwe.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- tumixivig.weebly.com
- babinekisifuve.weebly.com
- jukafubu.weebly.com
- zegojipoxe.weebly.com
- nubojubixuxo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report