SUSPICIOUS — normal_5f8715547da07.pdf
SUSPICIOUS — normal_5f8715547da07.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7a27e293cddb2bea6356f75702a30901164e898482d02890fc7e59d996d0a93c - SHA-1:
a4245ae1f97e212755294a047a783c528a693f75 - MD5:
5c68e8313a3f31db55a7d80fd07dad50 - ssdeep:
768:xgGzpDBeU9O0Ccityanp4eR+yvFhTDvzGU3sXPGdmzSQJ+isXSS0DGeLtndl0Viw:CGFNeJFh/rGU8XPGqS+BS0bzAi7eV2lu - TLSH:
T122328DF360A7DC8C7AC79B136DAB2695519AC7486137EB504888772DC0BC67EBF10860 - Submitted as: normal_5f8715547da07.pdf
- File type: pdf · Size: 45889 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=technically+speaking+by+chris+wilkinson+pdf, https://cdn.shopify.com/s/files/1/0429/9587/5989/files/self_vs_self_lender.pdf, https://cdn.shopify.com/s/files/1/0494/5929/8471/files/the_greatest_showman_reimagined_google_drive.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=technically+speaking+by+chris+wilkinson+pdf
- https://cdn.shopify.com/s/files/1/0429/9587/5989/files/self_vs_self_lender.pdf
- https://cdn.shopify.com/s/files/1/0432/0844/2020/files/65102241795.pdf
- https://cdn.shopify.com/s/files/1/0494/5929/8471/files/the_greatest_showman_reimagined_google_drive.pdf
- https://cdn.shopify.com/s/files/1/0483/8837/4680/files/zombie_age_2_apk_mod_unlimited_cash_and_coins.pdf
- https://site-1039895.mozfiles.com/files/1039895/65524412454.pdf
- https://site-1043791.mozfiles.com/files/1043791/bafemojibeduv.pdf
- https://site-1038472.mozfiles.com/files/1038472/46021971889.pdf
- https://site-1043559.mozfiles.com/files/1043559/manofoliriluzemaxemidix.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f870920c8535.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f86fab936f56.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f87040dee9c7.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f86ff819d80e.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f87135f96c05.pdf
- https://uploads.strikinglycdn.com/files/0f2fedc7-9330-4007-9639-767986b4ef23/58438837417.pdf
- https://uploads.strikinglycdn.com/files/0dacd7a4-d219-4729-8169-5169d5fac187/xawinumotubowo.pdf
- https://uploads.strikinglycdn.com/files/34c998d7-717a-490a-99fd-51375109b84c/44978976092.pdf
- https://uploads.strikinglycdn.com/files/7bbba146-56b9-4ffa-aa99-45683a925df4/16252258790.pdf
- https://uploads.strikinglycdn.com/files/8ce48ef7-a993-4c85-a616-a23f677439e5/rutuwepil.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f86ff8302644.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f870f4addf52.pdf
- https://cdn-cms.f-static.net/uploads/4365552/normal_5f870158b84f9.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f86f5f33e9c2.pdf
- https://cdn-cms.f-static.net/uploads/4365657/normal_5f86f465952ec.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1039895.mozfiles.com
- site-1043791.mozfiles.com
- site-1038472.mozfiles.com
- site-1043559.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report