SUSPICIOUS — normal_5f8784049c0a4.pdf
SUSPICIOUS — normal_5f8784049c0a4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
65a0e99ed1692ce2caac409b1597d6e3490ceb1d6b07217d64767154b2f043c2 - SHA-1:
921603fae1dfca11ae560f7a6448d9005a3b06b1 - MD5:
b1bb3a9e33fb6eaa26dce27dd1856ff9 - ssdeep:
768:DgGzpD+poEuCilRb28q996vy+EoMwFQWLm/sg:8GFapNBYvy+3BK/sg - TLSH:
T15D306CF311A7ED8C7E4BBB036DB701A9448AD34CA136A360458C7B2DD1BC6BD6E10961 - Submitted as: normal_5f8784049c0a4.pdf
- File type: pdf · Size: 37860 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=bissell+proheat+model+25a32+manual, https://uploads.strikinglycdn.com/files/0902de52-ad64-4cbb-8bb7-93ca0771bdc1/panavezutavi.pdf, https://uploads.strikinglycdn.com/files/09b9c2fc-e187-4193-9e09-0ca5d806915c/2437520503.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=bissell+proheat+model+25a32+manual
- https://uploads.strikinglycdn.com/files/0902de52-ad64-4cbb-8bb7-93ca0771bdc1/panavezutavi.pdf
- https://uploads.strikinglycdn.com/files/09b9c2fc-e187-4193-9e09-0ca5d806915c/2437520503.pdf
- https://uploads.strikinglycdn.com/files/03ec6c57-612d-47d8-b3ba-edd3600a435b/tomirenoliraluzefirow.pdf
- https://uploads.strikinglycdn.com/files/07bf0af8-4626-4101-b9e3-ff59b75bd264/sisifuva.pdf
- https://uploads.strikinglycdn.com/files/10d076ac-e399-4b17-adb4-95a0f631cd5c/84146420357.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/1181add08fecfe.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/5a2e20d42e55.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/katozuliwamu.pdf
- https://mijisurux.weebly.com/uploads/1/3/1/0/131070147/kosopewaverobikedowo.pdf
- https://liwevapazu.weebly.com/uploads/1/3/1/0/131071299/df0fb.pdf
- https://cdn.shopify.com/s/files/1/0436/3144/4128/files/gasoxadifibapebomaju.pdf
- https://cdn.shopify.com/s/files/1/0496/1956/6743/files/2.5_solving_compound_inequalities_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0439/4336/2715/files/65616314096.pdf
- https://cdn.shopify.com/s/files/1/0430/6262/4417/files/4550664466.pdf
- https://cdn.shopify.com/s/files/1/0485/3222/6203/files/samsung_525d_manual.pdf
- https://uploads.strikinglycdn.com/files/e992d2da-5610-4cf9-9fb6-a1362de65349/29604509861.pdf
- https://uploads.strikinglycdn.com/files/d40e13e5-95bb-44d9-9a71-e808375a82cc/21653959322.pdf
- https://uploads.strikinglycdn.com/files/114b9c21-1037-4b63-b8f5-d5c2b325acea/72168787573.pdf
- https://uploads.strikinglycdn.com/files/49073c9f-05a5-44fd-b758-911ae1f053e1/fatupadowe.pdf
- https://uploads.strikinglycdn.com/files/1fd38fa2-b002-4cc4-8775-aa3c945ec3cc/fuzejubikupinejewidejula.pdf
- https://site-1038969.mozfiles.com/files/1038969/32283620191.pdf
- https://site-1039398.mozfiles.com/files/1039398/83178914670.pdf
- https://site-1039421.mozfiles.com/files/1039421/jokewol.pdf
- https://site-1037192.mozfiles.com/files/1037192/30298259967.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- vozunutav.weebly.com
- zesopupejilit.weebly.com
- nudojafobedem.weebly.com
- mijisurux.weebly.com
- liwevapazu.weebly.com
- cdn.shopify.com
- site-1038969.mozfiles.com
- site-1039398.mozfiles.com
- site-1039421.mozfiles.com
- site-1037192.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report