SUSPICIOUS — normal_5f87fec806a89.pdf
SUSPICIOUS — normal_5f87fec806a89.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
5e3e8ef1b90a9dbb6fafb7211112e55e8ef045ab893cb743cf34ccc8b819282d - SHA-1:
721368bff3e8d4bd5d8a5f0d6ca1f0759ad6bf79 - MD5:
cf9ae8d4b57339c3bf19bf1016593d63 - ssdeep:
768:tgGzpD3pzBMQgA/wmegpkVhHTkaFTmdzK3wIu8aXaPQdExD9i4i0jkJ5oK:OGFTpEFdtu8yDdExDRIJiK - TLSH:
T132326BF310A7EC0CBACA9F076EAB255A904AD7489133EA50858C332CD47C6BD7F50960 - Submitted as: normal_5f87fec806a89.pdf
- File type: pdf · Size: 46686 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=5x7+envelope+template+pdf, https://cdn.shopify.com/s/files/1/0435/0482/8580/files/16647472014.pdf, https://cdn.shopify.com/s/files/1/0497/8311/1831/files/games_66_at_school_unblocked.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=5x7+envelope+template+pdf
- https://cdn.shopify.com/s/files/1/0435/0482/8580/files/16647472014.pdf
- https://cdn.shopify.com/s/files/1/0497/8311/1831/files/games_66_at_school_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0430/7098/0245/files/kramer_funeral_home_alexandria_la.pdf
- https://cdn-cms.f-static.net/uploads/4367271/normal_5f87abcd497bd.pdf
- https://cdn-cms.f-static.net/uploads/4366668/normal_5f877e52deddc.pdf
- https://cdn-cms.f-static.net/uploads/4368782/normal_5f87d4897e010.pdf
- https://site-1042501.mozfiles.com/files/1042501/pexusofikofuvuv.pdf
- https://site-1040224.mozfiles.com/files/1040224/54178117804.pdf
- https://site-1048457.mozfiles.com/files/1048457/kobidegafamewerutodi.pdf
- https://site-1042181.mozfiles.com/files/1042181/33111115975.pdf
- https://site-1038422.mozfiles.com/files/1038422/jefobilofebemosuju.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f86f83422fcf.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f870207cb6ff.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f87c5f0198d9.pdf
- https://cdn-cms.f-static.net/uploads/4366358/normal_5f873c66c05ec.pdf
- https://cdn.shopify.com/s/files/1/0499/2624/2472/files/suruzaxiwixare.pdf
- https://cdn.shopify.com/s/files/1/0483/8916/1128/files/riduwidamawadefidaloxupi.pdf
- https://cdn.shopify.com/s/files/1/0498/7371/5361/files/terrarium_tv_apk_alternative_android.pdf
- https://cdn.shopify.com/s/files/1/0431/7626/3841/files/73516755459.pdf
- https://cdn.shopify.com/s/files/1/0500/2549/6736/files/javascript_regex_tutorial.pdf
- https://site-1039992.mozfiles.com/files/1039992/tikajemujapikegijokomad.pdf
- https://site-1044238.mozfiles.com/files/1044238/pajir.pdf
- https://site-1040675.mozfiles.com/files/1040675/jbl_e25bt_wireless_in-ear_headphones_manual.pdf
- https://site-1039789.mozfiles.com/files/1039789/dadew.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1042501.mozfiles.com
- site-1040224.mozfiles.com
- site-1048457.mozfiles.com
- site-1042181.mozfiles.com
- site-1038422.mozfiles.com
- site-1039992.mozfiles.com
- site-1044238.mozfiles.com
- site-1040675.mozfiles.com
- site-1039789.mozfiles.com
- site-1038378.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report