SUSPICIOUS — normal_5f870a688824b.pdf
SUSPICIOUS — normal_5f870a688824b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2354c80548da2adf110f205a40aad77a66ed1e708b202a631d01dbef0d72e711 - SHA-1:
500226d21673de27a85859df925b604ebc6d23fa - MD5:
c24eb10ee72ab03678ea3e59c5ccd83c - ssdeep:
768:8LgGzpDhp1Aie36qZ4cFa0zOQeWxmypZ6Y6ZzPhXwk3Uqbko4yIX6N/hN+7cv:ZGFlpCzOQ9xmuorhgk3UITiqN/H3v - TLSH:
T1FF329FF710A7ED8C7A8E2F07ADA70159A18AD38D6137876004C87B7DD4BCAED2E10561 - Submitted as: normal_5f870a688824b.pdf
- File type: pdf · Size: 44956 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=fifa+mobile+20+release+date+on+android, https://cdn-cms.f-static.net/uploads/4365653/normal_5f8707716e8ca.pdf, https://cdn-cms.f-static.net/uploads/4366057/normal_5f8707e5238e9.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=fifa+mobile+20+release+date+on+android
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f8707716e8ca.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f8707e5238e9.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f8708feae79a.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f86f9188dda8.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f86fed978c71.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f8706dd16ffe.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f86fa16347a3.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f86f43ac442e.pdf
- https://uploads.strikinglycdn.com/files/1a6f002b-b3a7-4aa2-b893-81e79e784357/mujavonigewetapigik.pdf
- https://uploads.strikinglycdn.com/files/fabcdeaa-a55a-4ddd-9827-114ce6d13c5e/zojizivomel.pdf
- https://uploads.strikinglycdn.com/files/a8d02c88-2196-4b78-b02b-ea87c60de85d/xigaxulebovepejit.pdf
- https://uploads.strikinglycdn.com/files/4deb1765-b16a-4e24-81c1-3bbb2fd93653/93330124096.pdf
- https://uploads.strikinglycdn.com/files/81311ded-77a8-4d20-ab64-3dda83105f24/18614167389.pdf
- https://uploads.strikinglycdn.com/files/ae81ddbd-6067-4acb-9822-424b56168e12/11192366102.pdf
- https://uploads.strikinglycdn.com/files/d136b978-8d8b-4c5c-a099-9c43519909af/21191464284.pdf
- https://uploads.strikinglycdn.com/files/cae45fc6-2f8e-432b-a099-0c19c61aa5d6/mirusab.pdf
- https://uploads.strikinglycdn.com/files/547bc7b3-64bf-4963-b1ae-3521c69d2234/43645604506.pdf
- https://uploads.strikinglycdn.com/files/a1038133-ff50-40b0-aedc-586cfaef0a2b/73614410886.pdf
- https://uploads.strikinglycdn.com/files/643dbd98-cc31-45b8-8b44-4c8f635f3e2a/66812650724.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/8742796.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- zoxuzuxebexot.weebly.com
- mogilifus.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report