SUSPICIOUS — normal_5f8e6ebe5600e.pdf
SUSPICIOUS — normal_5f8e6ebe5600e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
55acc4d47b4ee648c81b83244e46bdccf5c3dbe9a13ed2d220da643795a2cb2a - SHA-1:
be0ca31239c85599375082ca98715da40ff406ce - MD5:
aa1a83c3be187d6d2792eba043486eed - ssdeep:
768:xTgGzpDzpnr4NVDIjMi3adUDa2rUxeMr8ndMwP0j+UHogo6S48FIzUE3p:2GFHprrModMwP0Ta6SHIzUE3p - TLSH:
T1FB327CF31493ED8C3A879B83AEB711993199D2C86136936149CC7B2CC0BC6BD6F11961 - Submitted as: normal_5f8e6ebe5600e.pdf
- File type: pdf · Size: 44809 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=facebook+full+site+login+android, https://cdn-cms.f-static.net/uploads/4368475/normal_5f8e39566d283.pdf, https://cdn-cms.f-static.net/uploads/4365628/normal_5f88f2c3de283.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=facebook+full+site+login+android
- https://cdn-cms.f-static.net/uploads/4368475/normal_5f8e39566d283.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f88f2c3de283.pdf
- https://cdn-cms.f-static.net/uploads/4375517/normal_5f8b987e0b559.pdf
- https://cdn-cms.f-static.net/uploads/4370263/normal_5f8d91ddefa92.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f8bf76a6a874.pdf
- https://cdn.shopify.com/s/files/1/0497/2468/6493/files/gta_liberty_city_stories_cheats_xbox_360_lost_and_damned.pdf
- https://cdn.shopify.com/s/files/1/0433/5111/3887/files/razas_de_conejos_en_colombia.pdf
- https://cdn.shopify.com/s/files/1/0428/5690/6911/files/masijufobanevilefisa.pdf
- https://cdn.shopify.com/s/files/1/0484/3316/8552/files/jan_ken_po_gakko.pdf
- https://uploads.strikinglycdn.com/files/f221dea5-1ff4-431f-b9cb-f190779a6c1c/fumitoverosurux.pdf
- https://uploads.strikinglycdn.com/files/3a9181fc-6854-4e0f-ac9c-183d7fe6b8da/legezopur.pdf
- https://uploads.strikinglycdn.com/files/dc27ee5e-e09d-4a7f-a9ff-5eda13082d85/38148786386.pdf
- https://uploads.strikinglycdn.com/files/f00701e3-984f-4d6b-b03d-54b92416959b/33995053459.pdf
- https://uploads.strikinglycdn.com/files/1df9e6a0-5ac9-4685-bd23-84dd42abcbf5/vimipefipokokiz.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/1185260.pdf
- https://lipowuripipu.weebly.com/uploads/1/3/1/3/131378852/zetenexo.pdf
- https://digafixi.weebly.com/uploads/1/3/0/7/130776371/xevon.pdf
- https://ruwopevod.weebly.com/uploads/1/3/1/3/131397973/50af8fd7b75.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/3703292.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/5e8d256f2b.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/ruvewa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- vodipewelo.weebly.com
- lipowuripipu.weebly.com
- digafixi.weebly.com
- ruwopevod.weebly.com
- tipefejiri.weebly.com
- sibakixode.weebly.com
- ditiwudo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report