SUSPICIOUS — normal_5f87b0c3a35a8.pdf
SUSPICIOUS — normal_5f87b0c3a35a8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
338fb5e46789449597f46fd7d8a91912894c40310369554755389071d7ea313b - SHA-1:
bfed59ab1967a187294bf837a51afa19104a74c1 - MD5:
089ce5e9251767b4e763a475df20d6a1 - ssdeep:
768:1gGzpDZerXc43G/etiMA0Gfqa8KfHb2shPjZDpsWbObQwSCVWt8kq6:mGFtepGdoA/ishPVDp/CMwSgm8kq6 - TLSH:
T15F327DF35097EC8C7A8EAF039EAB105D614AD78C313297A094C8772DD47C6AD6E40E61 - Submitted as: normal_5f87b0c3a35a8.pdf
- File type: pdf · Size: 44518 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=hundred+square+chart+pdf, https://uploads.strikinglycdn.com/files/fda1a0a6-1b56-46f7-9616-a493fbd2bd72/86765266235.pdf, https://uploads.strikinglycdn.com/files/a9191ef4-b089-4325-9b49-d2e3acb48fe8/96546506299.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=hundred+square+chart+pdf
- https://uploads.strikinglycdn.com/files/fda1a0a6-1b56-46f7-9616-a493fbd2bd72/86765266235.pdf
- https://uploads.strikinglycdn.com/files/a9191ef4-b089-4325-9b49-d2e3acb48fe8/96546506299.pdf
- https://uploads.strikinglycdn.com/files/06703618-32ca-45b4-9cf9-9827172f7cda/3051799790.pdf
- https://uploads.strikinglycdn.com/files/89f5b7ab-826c-4123-ab57-c123603686bf/94117547035.pdf
- https://uploads.strikinglycdn.com/files/12769b67-1c2d-4b7b-82b5-2d2a15a1b950/fedolinebi.pdf
- https://site-1040036.mozfiles.com/files/1040036/70199752890.pdf
- https://site-1043239.mozfiles.com/files/1043239/wapikoviwex.pdf
- https://site-1038743.mozfiles.com/files/1038743/sogijume.pdf
- https://uploads.strikinglycdn.com/files/3303439d-6692-4031-a8c4-96b01ffcb76c/88555345225.pdf
- https://uploads.strikinglycdn.com/files/9987689e-5315-438a-a4b1-cf31e13fea93/kelatafejeta.pdf
- https://uploads.strikinglycdn.com/files/51a8c3ad-ae9b-4379-8cf3-6078a9deb493/67671669978.pdf
- https://uploads.strikinglycdn.com/files/376fac26-a190-45aa-b1ae-d34c6a6003b1/63876002993.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/7304884.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/1d1f8ecc085ca.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/ratefunerod.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/646693.pdf
- https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/juniwotusupuvafodif.pdf
- https://cdn-cms.f-static.net/uploads/4366042/normal_5f86f499dd372.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f870c9be9686.pdf
- https://cdn-cms.f-static.net/uploads/4369168/normal_5f87aaade670b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1040036.mozfiles.com
- site-1043239.mozfiles.com
- site-1038743.mozfiles.com
- genigudepa.weebly.com
- mogilifus.weebly.com
- dutitujazekap.weebly.com
- nobinetezo.weebly.com
- viwuwobigoku.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report