SUSPICIOUS — normal_5f8715ac25799.pdf
SUSPICIOUS — normal_5f8715ac25799.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
4809a3ccf013d17382a947cea64ee19185700de5393bd9635ba540629ed6fe63 - SHA-1:
137c50b05b3d783e5de6a4d95a6fe5d767ae4e45 - MD5:
6d44ba3a4a441112b954ab104755eb3b - ssdeep:
768:zugGzpDJpYpA2OFqN72GlGV/wmCa4TFCRT8wKXf+2JOTvetF9qFCYDSVnMYQ67yp:vGFlpIpI/wDYRT7TTve7Oejz2NT - TLSH:
T144338CF34497EC8C7A8B5B039EAB10AD91CACA4D91369741458C723DC07C9EEAF10665 - Submitted as: normal_5f8715ac25799.pdf
- File type: pdf · Size: 48192 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=bleach+mobile+3d+download+for+android, https://uploads.strikinglycdn.com/files/c675130b-9565-4c2b-b70d-12a3a8c0fac6/lamole.pdf, https://uploads.strikinglycdn.com/files/ac0dd661-377c-4253-9794-94aa01819796/nixuzarafa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=bleach+mobile+3d+download+for+android
- https://uploads.strikinglycdn.com/files/c675130b-9565-4c2b-b70d-12a3a8c0fac6/lamole.pdf
- https://uploads.strikinglycdn.com/files/ac0dd661-377c-4253-9794-94aa01819796/nixuzarafa.pdf
- https://uploads.strikinglycdn.com/files/87cffb54-6692-40a5-97c0-4f7d0b50f319/wuparadoxowotuwiwojo.pdf
- https://uploads.strikinglycdn.com/files/c84ced85-43b2-4d61-b085-f4ae5987b931/sesalosugig.pdf
- https://uploads.strikinglycdn.com/files/757a7779-d34e-403a-ac1a-8595b06cf5db/54530839371.pdf
- https://site-1041084.mozfiles.com/files/1041084/gorotiv.pdf
- https://site-1041295.mozfiles.com/files/1041295/zisinabefixegogufivifawan.pdf
- https://site-1036930.mozfiles.com/files/1036930/kosizidinanawavovu.pdf
- https://site-1041086.mozfiles.com/files/1041086/95494405772.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/busixakowun_zefisuni.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/xopevu_vilugarokobijos_fimorekon.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/c25f730.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/kezedivalo-bolumukejufufik.pdf
- https://uploads.strikinglycdn.com/files/03e4add5-93b0-4782-83f1-652b073e5fad/52429987877.pdf
- https://uploads.strikinglycdn.com/files/05f3a80c-9566-4fe9-bb83-57ee0f8a5c67/38245402921.pdf
- https://uploads.strikinglycdn.com/files/18912767-7cbe-46c7-9691-f836adac699e/53107270323.pdf
- https://uploads.strikinglycdn.com/files/9948a7bf-886a-4a47-940d-41c9fa41827a/40369985203.pdf
- https://uploads.strikinglycdn.com/files/df6f624d-490b-4a5d-ab21-2680cb82f89a/33722787909.pdf
- https://cdn.shopify.com/s/files/1/0266/9009/3239/files/xumowofoniriz.pdf
- https://cdn.shopify.com/s/files/1/0496/2028/7639/files/english_idioms_a_to_z.pdf
- https://cdn.shopify.com/s/files/1/0477/6185/0524/files/43731119593.pdf
- https://cdn.shopify.com/s/files/1/0479/2113/5783/files/69457432504.pdf
- https://cdn.shopify.com/s/files/1/0471/0649/0518/files/84568848152.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/domovodibaposix.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1041084.mozfiles.com
- site-1041295.mozfiles.com
- site-1036930.mozfiles.com
- site-1041086.mozfiles.com
- jakedekokobara.weebly.com
- jawasolasazilem.weebly.com
- gevafitasib.weebly.com
- dimaxafazeza.weebly.com
- cdn.shopify.com
- guwomenod.weebly.com
- mogilifus.weebly.com
- gimejexoxixaza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report