SUSPICIOUS — normal_5f872cb382254.pdf
SUSPICIOUS — normal_5f872cb382254.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
4ad4c9a460c9e0d1c57d764e8e6c5f93cc9d26caf68e32029f1af7309a71da2b - SHA-1:
6f98eb575e0a4efd8b775a65094eb95002d3a250 - MD5:
91191d9cd21cac9213318561dcaec945 - ssdeep:
768:wigGzpDIp5on7xG28fWqr/fPFUpznhBG2lW49m9u2lA4ZOTmBolY99KpgoVm:+GFkp5tFUpzn/G2luRAIOTIUG9boVm - TLSH:
T119327CF310A7ED8C3A8B9B179DF7115A648AD74D5033A2905988272CD5BC6FE3F40A12 - Submitted as: normal_5f872cb382254.pdf
- File type: pdf · Size: 44718 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=buat+akun+facebook+baru+di+android, https://cdn.shopify.com/s/files/1/0437/1028/3931/files/minecraft_tower_defense_unblocked_games.pdf, https://cdn.shopify.com/s/files/1/0496/2825/0276/files/79008774593.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=buat+akun+facebook+baru+di+android
- https://cdn.shopify.com/s/files/1/0437/1028/3931/files/minecraft_tower_defense_unblocked_games.pdf
- https://cdn.shopify.com/s/files/1/0496/2825/0276/files/79008774593.pdf
- https://cdn.shopify.com/s/files/1/0496/7700/9060/files/bizalajerebunika.pdf
- https://cdn.shopify.com/s/files/1/0486/5327/1208/files/82664569590.pdf
- https://cdn.shopify.com/s/files/1/0434/8765/8150/files/white_wine_in_the_sun_chords.pdf
- https://cdn.shopify.com/s/files/1/0499/8597/8518/files/voromozunapovur.pdf
- https://cdn.shopify.com/s/files/1/0476/5152/0678/files/desirawaxagani.pdf
- https://cdn.shopify.com/s/files/1/0438/4276/4962/files/manazuvisuxikazopejidiw.pdf
- https://cdn.shopify.com/s/files/1/0435/0282/9734/files/kunukaxawuvunero.pdf
- https://cdn.shopify.com/s/files/1/0498/8511/8638/files/reception_conditions_directive.pdf
- https://cdn.shopify.com/s/files/1/0429/3669/6995/files/argumentative_paragraph_examples_for_college.pdf
- https://cdn.shopify.com/s/files/1/0484/8795/6641/files/new_prince_of_tennis_manga_download.pdf
- https://site-1040988.mozfiles.com/files/1040988/13605701082.pdf
- https://site-1040218.mozfiles.com/files/1040218/wijavuxosojezo.pdf
- https://site-1036696.mozfiles.com/files/1036696/78719887572.pdf
- https://uploads.strikinglycdn.com/files/edf2182e-4ed0-47e1-ad2f-a3725f34eecd/33480095714.pdf
- https://uploads.strikinglycdn.com/files/93097eb2-6ed9-4c68-9fa3-df5a2db041ec/nebadonidebiwikugav.pdf
- https://uploads.strikinglycdn.com/files/3ed08f05-b5b2-43ec-95eb-33f7fa431ed4/64324346065.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/1349961.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/pejajofedaxevaw_kozadesupuke.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3532345.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/be0770a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1040988.mozfiles.com
- site-1040218.mozfiles.com
- site-1036696.mozfiles.com
- uploads.strikinglycdn.com
- zesopupejilit.weebly.com
- guwomenod.weebly.com
- zoxuzuxebexot.weebly.com
- vuzevarezevarot.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report