SUSPICIOUS — normal_5f870ef8845ca.pdf
SUSPICIOUS — normal_5f870ef8845ca.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
49d610d1c2fb5322e8ddc823655c5cbfd955350dc617c895d87ab23e7314b97c - SHA-1:
814fc16698dccd49cba2de810c859c960ddbdc29 - MD5:
41924f827d5fb2b95b0b2a6db3d6b10d - ssdeep:
1536:FGF2upGIyEm01D1m6bbWOROuoHEir5KGO+AQGOiuaA:YF2upG3I1m1OUuoHLAGO+AQNiup - TLSH:
T14E33BFF354A3DD4D798B9B43BDBA21551589D34C6237AB60588C372DC8BC6BEBE00420 - Submitted as: normal_5f870ef8845ca.pdf
- File type: pdf · Size: 49595 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=c+books+for+beginners+pdf, https://uploads.strikinglycdn.com/files/bda70001-e3c2-492f-9e11-6211b46f9af9/3770635609.pdf, https://uploads.strikinglycdn.com/files/f97a689e-c105-4494-89ae-fe518038af07/vigimuka.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=c+books+for+beginners+pdf
- https://uploads.strikinglycdn.com/files/bda70001-e3c2-492f-9e11-6211b46f9af9/3770635609.pdf
- https://uploads.strikinglycdn.com/files/f97a689e-c105-4494-89ae-fe518038af07/vigimuka.pdf
- https://uploads.strikinglycdn.com/files/b5857d1d-c5f2-43db-b6a9-4653d3635e17/sumijawukibezasud.pdf
- https://uploads.strikinglycdn.com/files/46d7cb39-772f-4af0-a937-e2ac695495ea/nawidi.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f87005e3a783.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f87098cb5def.pdf
- https://uploads.strikinglycdn.com/files/db7dfb97-b898-4848-9667-4bf527a30fc7/32743917072.pdf
- https://uploads.strikinglycdn.com/files/cf8f7c16-82a3-402b-bf82-0ed490b2354b/manuvusij.pdf
- https://uploads.strikinglycdn.com/files/503d6408-ac15-4548-8243-b859521e1d90/32344256344.pdf
- https://uploads.strikinglycdn.com/files/81a1275f-df6c-42d6-9d44-10e1b63e45bf/roguwiv.pdf
- https://cdn.shopify.com/s/files/1/0435/2661/9287/files/marriage_license_york_maine.pdf
- https://cdn.shopify.com/s/files/1/0433/0356/7515/files/dejomewiji.pdf
- https://cdn.shopify.com/s/files/1/0482/5251/8554/files/pine_bed_frames.pdf
- https://cdn.shopify.com/s/files/1/0433/7811/4727/files/70761375934.pdf
- https://cdn.shopify.com/s/files/1/0483/5901/4551/files/quick_shine_deep_cleaner_lowes.pdf
- https://site-1037835.mozfiles.com/files/1037835/fosulinamifuri.pdf
- https://site-1039307.mozfiles.com/files/1039307/44029966271.pdf
- https://site-1038455.mozfiles.com/files/1038455/20333168617.pdf
- https://site-1042886.mozfiles.com/files/1042886/wodewafobobemenupologi.pdf
- https://site-1042498.mozfiles.com/files/1042498/61097005943.pdf
- https://cdn.shopify.com/s/files/1/0434/4823/8241/files/removing_a_toilet_tank.pdf
- https://cdn.shopify.com/s/files/1/0435/6590/8123/files/puliwutixajubuko.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1037835.mozfiles.com
- site-1039307.mozfiles.com
- site-1038455.mozfiles.com
- site-1042886.mozfiles.com
- site-1042498.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report