SUSPICIOUS — normal_5f88d3e680373.pdf
SUSPICIOUS — normal_5f88d3e680373.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
3ffc987a58bdbc276d7c667c1996ee97c3d3bca6ebcf83b60eb39bbf9aa692a4 - SHA-1:
bf49be9213aaa09944b0271775e841e857b46716 - MD5:
b69eca94060f73dfa32f46d146324fd9 - ssdeep:
768:LgGzpDdpTxGqSGm3cOYhUh8PC7fqtyrnGwKl5qleHZ99pB/s2B:0GFhpTcxLrGdl5qSZpB/s2B - TLSH:
T100317DF700A7ED8C7A8EAB43AEA7115D618AD38D6132D790448C772CD0BCAAD7F50611 - Submitted as: normal_5f88d3e680373.pdf
- File type: pdf · Size: 39366 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=suffix+ly+worksheets+for+2nd+grade, https://uploads.strikinglycdn.com/files/f54e9716-1aed-4191-9a6c-3ef9d840c100/47728677555.pdf, https://uploads.strikinglycdn.com/files/fff624ad-5c55-4317-bf3f-93820bf99d2c/damabuliles.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=suffix+ly+worksheets+for+2nd+grade
- https://uploads.strikinglycdn.com/files/f54e9716-1aed-4191-9a6c-3ef9d840c100/47728677555.pdf
- https://uploads.strikinglycdn.com/files/fff624ad-5c55-4317-bf3f-93820bf99d2c/damabuliles.pdf
- https://uploads.strikinglycdn.com/files/938268b9-5541-466e-b286-f14737213bd7/16298497640.pdf
- https://uploads.strikinglycdn.com/files/e3189a28-d818-4faf-8314-2aef1e67e8e4/lofajulagevaxibos.pdf
- https://site-1040256.mozfiles.com/files/1040256/27311554906.pdf
- https://site-1040244.mozfiles.com/files/1040244/jawenegejebanobekati.pdf
- https://site-1044239.mozfiles.com/files/1044239/geturimepemanokugut.pdf
- https://site-1041285.mozfiles.com/files/1041285/lunipij.pdf
- https://cdn.shopify.com/s/files/1/0493/8819/1906/files/3101103685.pdf
- https://cdn.shopify.com/s/files/1/0432/5841/3216/files/helen_waddell_the_desert_fathers.pdf
- https://cdn.shopify.com/s/files/1/0487/0946/8310/files/thermaltake_core_v21_manual.pdf
- https://cdn.shopify.com/s/files/1/0483/5478/7477/files/tecnica_de_lactancia_materna_oms.pdf
- https://cdn.shopify.com/s/files/1/0433/7922/8837/files/lincoln_center_chapel_hill_nc.pdf
- https://cdn.shopify.com/s/files/1/0433/7496/8997/files/94016019022.pdf
- https://cdn.shopify.com/s/files/1/0482/6664/1570/files/what_time_is_the_44_bus_coming.pdf
- https://cdn.shopify.com/s/files/1/0496/6917/7497/files/loredojuketilo.pdf
- https://cdn.shopify.com/s/files/1/0497/8524/1759/files/business_analysis_tools.pdf
- https://cdn.shopify.com/s/files/1/0437/6494/0961/files/62259032924.pdf
- https://cdn-cms.f-static.net/uploads/4367951/normal_5f87a49813b07.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f883b7553ffd.pdf
- https://cdn.shopify.com/s/files/1/0428/9472/1187/files/sly_cooper_playable_characters.pdf
- https://cdn.shopify.com/s/files/1/0485/5096/9529/files/46086807628.pdf
- https://cdn.shopify.com/s/files/1/0484/3012/1112/files/craftsman_16_42cc_gas_chainsaw_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1040256.mozfiles.com
- site-1040244.mozfiles.com
- site-1044239.mozfiles.com
- site-1041285.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report