SUSPICIOUS — normal_5f876f264735a.pdf
SUSPICIOUS — normal_5f876f264735a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
40a43c4a2003b91a3ec58cff34a1a5415a4324fc7f614bb3a544a003b85ff196 - SHA-1:
188c3b07c042c99a296840ae3cca32674119e699 - MD5:
e6c13b93da531ae8923720e88701be40 - ssdeep:
768:GJgGzpDMeBTDQPeITnkmycfWGhMEhdv4fseISKSOEYhlvhcoZ1Sb4AdWTMcJKv:JGFQeIeI9BdqG1lSoZydWocJKv - TLSH:
T153349EF310A7DD4CBACBAB07AEE625585089C74C6173A7D44488772CC0BC76D7E11AA1 - Submitted as: normal_5f876f264735a.pdf
- File type: pdf · Size: 53791 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=best+pdf+edit+app+for+android, https://site-1039848.mozfiles.com/files/1039848/tuvilelanuxuwige.pdf, https://site-1038675.mozfiles.com/files/1038675/siluzewigutozuzosasufixi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=best+pdf+edit+app+for+android
- https://site-1039848.mozfiles.com/files/1039848/tuvilelanuxuwige.pdf
- https://site-1038675.mozfiles.com/files/1038675/siluzewigutozuzosasufixi.pdf
- https://site-1036821.mozfiles.com/files/1036821/nefebavekafetuwawivuderi.pdf
- https://site-1038729.mozfiles.com/files/1038729/27645990777.pdf
- https://cdn.shopify.com/s/files/1/0434/0101/9548/files/17103763964.pdf
- https://cdn.shopify.com/s/files/1/0485/9153/6288/files/4th_wedding_anniversary_gifts.pdf
- https://uploads.strikinglycdn.com/files/2495b41a-269e-414d-ad2d-68b0a2c7fc10/pogipawofe.pdf
- https://uploads.strikinglycdn.com/files/44996659-dd3c-4f0c-b0cb-719d7ed5ccaa/juwukizazevazemiduzimev.pdf
- https://uploads.strikinglycdn.com/files/a1f56894-b92b-4e95-a7d1-0ba83b8ae458/josada.pdf
- https://uploads.strikinglycdn.com/files/0793e668-303d-451b-9584-61aecb81862f/kegukusilidimo.pdf
- https://uploads.strikinglycdn.com/files/f8db6730-1318-4cc5-9d29-8cc4d961c60f/77195809935.pdf
- https://cdn-cms.f-static.net/uploads/4367923/normal_5f876e0c86cc4.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f876a1e7f21a.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f8730688b140.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f8746bd969f6.pdf
- https://cdn-cms.f-static.net/uploads/4368243/normal_5f876b9e966ba.pdf
- https://uploads.strikinglycdn.com/files/6081b09e-299c-4636-9172-2fca5ee8afb9/68357132816.pdf
- https://uploads.strikinglycdn.com/files/5fa7a7c2-3efe-40ba-b120-1a4fd262bb39/70629864582.pdf
- https://uploads.strikinglycdn.com/files/8e9fc60d-d4d9-499d-8fb0-4470b4a7f0e9/16504147962.pdf
- https://uploads.strikinglycdn.com/files/ded16b9a-0917-4506-8adc-0cb69090596b/tajokanibagufudebi.pdf
- https://uploads.strikinglycdn.com/files/32e6c3b2-2c58-464d-a39e-c59fe6fe80cc/20715669812.pdf
- https://uploads.strikinglycdn.com/files/87bd61d7-b9cb-44ff-8bbb-bf5c9f792198/36003774307.pdf
- https://uploads.strikinglycdn.com/files/29b5c291-a77a-473b-b024-dd857568a0d2/26950009554.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- site-1039848.mozfiles.com
- site-1038675.mozfiles.com
- site-1036821.mozfiles.com
- site-1038729.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report