SUSPICIOUS — normal_5f88da20d6332.pdf
SUSPICIOUS — normal_5f88da20d6332.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
2f8ae83b5f4cb04403ad0bac627169cee646c49b0e9573e8eea764c45f0adeda - SHA-1:
7a83e65e9557309ae975f1fd0622d86b2d8235aa - MD5:
764f269d24cac4a3cece9d6fdd55a526 - ssdeep:
768:pgGzpDupFi1BXTdUITZkQBZv4fvz11WDeqmBe+LHrCUi7e+T/nDBPw:KGFCpavRz4XQAeYHr66+bDBPw - TLSH:
T1FC338DF350A7DD8CBA8F6B179AA720A95089D34DA133979041DC3B2DC47C9BD7E80921 - Submitted as: normal_5f88da20d6332.pdf
- File type: pdf · Size: 49846 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=surprised+by+joy+lewis+pdf, https://site-1042875.mozfiles.com/files/1042875/zuxika.pdf, https://site-1038427.mozfiles.com/files/1038427/87655916456.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=surprised+by+joy+lewis+pdf
- https://site-1042875.mozfiles.com/files/1042875/zuxika.pdf
- https://site-1038427.mozfiles.com/files/1038427/87655916456.pdf
- https://site-1043408.mozfiles.com/files/1043408/mastitis_in_goat.pdf
- https://site-1042969.mozfiles.com/files/1042969/deperopimaxeranuxigema.pdf
- https://uploads.strikinglycdn.com/files/e3402c6f-02b9-46ee-a803-5e598d5b6152/mifotifilebulobux.pdf
- https://uploads.strikinglycdn.com/files/c26fe184-215c-4416-886f-8b04925397df/xipalevujiko.pdf
- https://uploads.strikinglycdn.com/files/0e00a9bb-45c9-4583-88e9-e2bb24d26ed2/pipufa.pdf
- https://site-1038772.mozfiles.com/files/1038772/momegokabalin.pdf
- https://site-1036929.mozfiles.com/files/1036929/46253806219.pdf
- https://site-1045404.mozfiles.com/files/1045404/jazapukuxuxinopujadok.pdf
- https://site-1041922.mozfiles.com/files/1041922/89416025716.pdf
- https://site-1039549.mozfiles.com/files/1039549/66822198726.pdf
- https://cdn-cms.f-static.net/uploads/4368999/normal_5f88ce643f0cc.pdf
- https://cdn-cms.f-static.net/uploads/4366989/normal_5f872abe4921c.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f873f4abd153.pdf
- https://uploads.strikinglycdn.com/files/651ac878-de5d-412e-8489-c0daadb134d3/22455056249.pdf
- https://uploads.strikinglycdn.com/files/42ab403b-3911-4fbf-8417-714f2f323932/zujibiwu.pdf
- https://uploads.strikinglycdn.com/files/4eaf2317-034f-4180-b800-871f3aa73d62/31643392959.pdf
- https://uploads.strikinglycdn.com/files/6a2e072e-db0f-4603-899a-d1a28fd7e887/8314304159.pdf
- https://uploads.strikinglycdn.com/files/cdfcd101-e976-454c-bc55-ec840a0f4154/tarunevotojag.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f88cdf861fbc.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f87b0deee945.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- site-1042875.mozfiles.com
- site-1038427.mozfiles.com
- site-1043408.mozfiles.com
- site-1042969.mozfiles.com
- uploads.strikinglycdn.com
- site-1038772.mozfiles.com
- site-1036929.mozfiles.com
- site-1045404.mozfiles.com
- site-1041922.mozfiles.com
- site-1039549.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report