SUSPICIOUS — normal_5f879d1ece5a2.pdf
SUSPICIOUS — normal_5f879d1ece5a2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
44b38eed7c64c1bcbf8fd8b9efbfb0f2aa2c21058b551a4db22de791c0eadfe7 - SHA-1:
87474cf94c0e2fee0ea2ad7caded94cc0f3a228e - MD5:
a111f09a2f56f26b3b3bc8dac92d4a22 - ssdeep:
768:ZgGzpDzpazltJ/CLoCoFKsd4/7Fbr1Lrp8kYg/2PXqJuy7+8tOTDS:aGFPpyreF1LN89kY6Juu+qOTDS - TLSH:
T12E317CF710A7DC4C7B879B57ADFB255A514AD24C6223D7A008987B2DD4BC2AE7E10820 - Submitted as: normal_5f879d1ece5a2.pdf
- File type: pdf · Size: 41350 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=school+leaving+certificate+pdf+download, https://cdn-cms.f-static.net/uploads/4366348/normal_5f87877cf0d97.pdf, https://cdn-cms.f-static.net/uploads/4367633/normal_5f876213ea485.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=school+leaving+certificate+pdf+download
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f87877cf0d97.pdf
- https://cdn-cms.f-static.net/uploads/4367633/normal_5f876213ea485.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f8702bb99816.pdf
- https://cdn-cms.f-static.net/uploads/4368970/normal_5f879c0a790d2.pdf
- https://cdn-cms.f-static.net/uploads/4367013/normal_5f87384c2e89b.pdf
- https://cdn-cms.f-static.net/uploads/4366622/normal_5f877e385f577.pdf
- https://uploads.strikinglycdn.com/files/fe64266d-cdba-4db5-ba98-3967fe45421f/93331506166.pdf
- https://uploads.strikinglycdn.com/files/34b551d7-5029-4a86-b608-25c6b5a3b5db/lomexala.pdf
- https://uploads.strikinglycdn.com/files/3f442165-f22b-4cbe-b878-83de67782e2f/ronogoworojafa.pdf
- https://uploads.strikinglycdn.com/files/bcf97dda-38d5-4801-b9dc-eb5804ecc0de/nukikidodukoterazegizawat.pdf
- https://cdn.shopify.com/s/files/1/0497/1056/3485/files/40484206513.pdf
- https://cdn.shopify.com/s/files/1/0433/7329/7820/files/harley_wide_glide_weight.pdf
- https://cdn.shopify.com/s/files/1/0497/7128/2586/files/vurizexilabisop.pdf
- https://cdn.shopify.com/s/files/1/0482/8617/1297/files/7643970673.pdf
- https://cdn.shopify.com/s/files/1/0429/4452/8550/files/what_is_a_mouth_geography_definition.pdf
- https://site-1039514.mozfiles.com/files/1039514/pomevuzedireduvezi.pdf
- https://site-1044198.mozfiles.com/files/1044198/lozevejavopuniruzifeku.pdf
- https://site-1039892.mozfiles.com/files/1039892/vulino.pdf
- https://site-1041933.mozfiles.com/files/1041933/90404634354.pdf
- https://uploads.strikinglycdn.com/files/9bc59a68-1923-4eb9-bb83-d9092909e535/biwipafot.pdf
- https://uploads.strikinglycdn.com/files/68b54aec-49eb-4b71-9028-23c0ca585c07/47235970602.pdf
- https://uploads.strikinglycdn.com/files/334b75ea-31c8-496b-aca3-75ce9a7908e6/13209585417.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1039514.mozfiles.com
- site-1044198.mozfiles.com
- site-1039892.mozfiles.com
- site-1041933.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report