SUSPICIOUS — normal_5f8eab7a1f90c.pdf
SUSPICIOUS — normal_5f8eab7a1f90c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
3bee1959c110015c4e39305395566bdae2026174b5477d4df04f49eda6d8443a - SHA-1:
d7a14ee4a62e0add03ae1ccd5e34a13a35c24113 - MD5:
a0be7d944e9e89b175aca545917ee3fe - ssdeep:
768:c5gGzpDmpo8USDFrsjsgPKRtTkWbJqP/Jta5uvBlqDxXKGxbWHbnR21WSehFZ/wE:c6GFSpo8qAO8DMubWR21WSuLgy - TLSH:
T14D327CF310BBDD8C3A86DB07BDEA2528954EDB8821329790558C676CC4BC77D6E50E20 - Submitted as: normal_5f8eab7a1f90c.pdf
- File type: pdf · Size: 45520 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=kiran+prakashan+railway+book+pdf, https://cdn.shopify.com/s/files/1/0502/2951/0324/files/jijobekukotupexuta.pdf, https://cdn.shopify.com/s/files/1/0498/0054/4418/files/pubitojovagev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=kiran+prakashan+railway+book+pdf
- https://cdn.shopify.com/s/files/1/0502/2951/0324/files/jijobekukotupexuta.pdf
- https://cdn.shopify.com/s/files/1/0498/0054/4418/files/pubitojovagev.pdf
- https://cdn.shopify.com/s/files/1/0481/5916/2521/files/dilawomudobuv.pdf
- https://uploads.strikinglycdn.com/files/beb9ac3b-091d-4135-aab6-7c2ce329ac39/17015179722.pdf
- https://uploads.strikinglycdn.com/files/fd18fdcb-e781-4394-bff8-e620e4adf3aa/gogeludanegalesiri.pdf
- https://uploads.strikinglycdn.com/files/5c22881e-3663-4a7d-a208-bd0d5ead9be6/familia_de_palabras_de_lapiz_ejemplo.pdf
- https://uploads.strikinglycdn.com/files/65bfdf9a-3956-4f4a-b79d-f9e5f8b3c590/nafekesofukepifag.pdf
- https://cdn-cms.f-static.net/uploads/4383128/normal_5f8e062743b87.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f89e8ec35c8f.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f87c8fbf2081.pdf
- https://cdn-cms.f-static.net/uploads/4370299/normal_5f8a79e7bcbfd.pdf
- https://cdn-cms.f-static.net/uploads/4371258/normal_5f893a25bea1e.pdf
- https://cdn-cms.f-static.net/uploads/4369524/normal_5f8ea35493414.pdf
- https://cdn-cms.f-static.net/uploads/4374688/normal_5f8c03b8f121d.pdf
- https://cdn-cms.f-static.net/uploads/4366653/normal_5f8a42ed33e12.pdf
- https://cdn-cms.f-static.net/uploads/4391898/normal_5f8e7e023e3b3.pdf
- https://uploads.strikinglycdn.com/files/0d4ed8a5-28d8-4213-b92a-cc1d4df536eb/piragabodunekimafejaboxi.pdf
- https://uploads.strikinglycdn.com/files/3f52560b-6f2f-432a-a1ad-fccd54911600/98535196835.pdf
- https://cdn-cms.f-static.net/uploads/4369189/normal_5f88a57a6d4ad.pdf
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f8affe2ac30a.pdf
- https://cdn-cms.f-static.net/uploads/4376120/normal_5f8dcaab94bcc.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report