SUSPICIOUS — normal_5f87c0816ab53.pdf
SUSPICIOUS — normal_5f87c0816ab53.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
52c33a60fcf28106a3782ef4b07b508bc3ca5fd9a4fed9c83464e0b6dacbfdef - SHA-1:
7c1a1ee072029e47a5a06010ebd7156f2f1eee5e - MD5:
9b4ca2d100faac86f5143f2f539df962 - ssdeep:
768:PgGzpDIpDzyh7+ncAMSjAq9jnMRvugVpW/fwl6a8nIOtDwPdMOGUYv/:4GF0pq93S17ql6lI6+dMb/v/ - TLSH:
T187339EF340A7ED4C798A6B079EE60159908AC78D60339BA045C8376DD4BC6FE7F10A61 - Submitted as: normal_5f87c0816ab53.pdf
- File type: pdf · Size: 48459 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=warlords+of+erehwon+pdf+download, https://uploads.strikinglycdn.com/files/70147386-bcf8-400d-b2c2-0aa4009edd69/86252114287.pdf, https://uploads.strikinglycdn.com/files/70de5c24-59a2-49bb-a4de-fda4f87cdc4f/mununuwuviwivowonuko.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=warlords+of+erehwon+pdf+download
- https://uploads.strikinglycdn.com/files/70147386-bcf8-400d-b2c2-0aa4009edd69/86252114287.pdf
- https://uploads.strikinglycdn.com/files/70de5c24-59a2-49bb-a4de-fda4f87cdc4f/mununuwuviwivowonuko.pdf
- https://uploads.strikinglycdn.com/files/6b1bc2b2-9c98-4722-90d2-e9ca0b2c3592/baluf.pdf
- https://uploads.strikinglycdn.com/files/865836e4-c916-4e82-ad8c-89d9b4d168ba/24255442677.pdf
- https://site-1043037.mozfiles.com/files/1043037/16601206316.pdf
- https://site-1037890.mozfiles.com/files/1037890/90936098334.pdf
- https://site-1039769.mozfiles.com/files/1039769/keurig_k10_mini_plus_owners_manual.pdf
- https://site-1041491.mozfiles.com/files/1041491/xirazexukutakilifaziza.pdf
- https://site-1040289.mozfiles.com/files/1040289/zokinovopezo.pdf
- https://site-1048220.mozfiles.com/files/1048220/669749038.pdf
- https://site-1040977.mozfiles.com/files/1040977/56544393625.pdf
- https://uploads.strikinglycdn.com/files/1fa9f1b2-8fbf-404f-b738-fa3e2730017c/66109590785.pdf
- https://uploads.strikinglycdn.com/files/fb55188e-6a79-4dc7-a4eb-78544aede0ae/dojomazosenikumosemaze.pdf
- https://uploads.strikinglycdn.com/files/7b6fae88-2090-42b9-b4c0-bce0cc47ef44/60618122291.pdf
- https://cdn-cms.f-static.net/uploads/4369158/normal_5f87ae234d70a.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f8706000c605.pdf
- https://uploads.strikinglycdn.com/files/ada048ac-0c02-445b-838a-87ad81a7201d/27027022215.pdf
- https://uploads.strikinglycdn.com/files/b23b5c56-70b1-4d41-8dd9-b6d6579566ad/95366743181.pdf
- https://uploads.strikinglycdn.com/files/d7294c19-1312-4bc6-a687-488b8704ccac/gepemuxagiwomawo.pdf
- https://uploads.strikinglycdn.com/files/25e09cde-b44a-4ab9-9a9b-ca610f6fb10a/30129352176.pdf
- https://uploads.strikinglycdn.com/files/ff51994d-4065-44e5-9e4e-593a067b8d1d/wokidosupi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1043037.mozfiles.com
- site-1037890.mozfiles.com
- site-1039769.mozfiles.com
- site-1041491.mozfiles.com
- site-1040289.mozfiles.com
- site-1048220.mozfiles.com
- site-1040977.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report