SUSPICIOUS — normal_5f890b8e404b5.pdf
SUSPICIOUS — normal_5f890b8e404b5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
7bcbd3fff13448231f0fe95ced68bb3ec499dda4229bb17a8690360a06f5a7fb - SHA-1:
dbc5ac0d323a6e4798ece195c84ae83a625866b3 - MD5:
5f03eed4c58a3b71a8474f685104a3ae - ssdeep:
768:zpgGzpDHZpHafQs5PS0tVtvi75ukHIaJLQlH9IgrV/hF3ojEh6tuXCQBB2NUs:2GFdpHWQsNt275H+V5F3ojEh6tJYBXs - TLSH:
T117327DF340B3ED4CBACBAB137EEA1119840DD64D507297A455887B2CC5BC2BE7E50A90 - Submitted as: normal_5f890b8e404b5.pdf
- File type: pdf · Size: 46212 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=2+player+android+games+same+device, https://uploads.strikinglycdn.com/files/3f6e5afa-de52-4b00-9e9e-22a803e0f3d2/4393735076.pdf, https://uploads.strikinglycdn.com/files/53ed542e-98bb-4ddd-9f10-29addc795b54/suwikebuv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=2+player+android+games+same+device
- https://uploads.strikinglycdn.com/files/3f6e5afa-de52-4b00-9e9e-22a803e0f3d2/4393735076.pdf
- https://uploads.strikinglycdn.com/files/53ed542e-98bb-4ddd-9f10-29addc795b54/suwikebuv.pdf
- https://uploads.strikinglycdn.com/files/b81ea364-be00-4f44-8120-d45bf3aa25e7/voxenine.pdf
- https://uploads.strikinglycdn.com/files/8dc42c0e-509e-46a5-ae1f-24475acc4b22/zeporanijatifebamowuveni.pdf
- https://uploads.strikinglycdn.com/files/28ddd1e4-69ac-40f9-9122-f5be48604661/xotefofopubituxijoz.pdf
- https://site-1038963.mozfiles.com/files/1038963/ribakosoxejube.pdf
- https://site-1040513.mozfiles.com/files/1040513/vunezapenejodaguwegara.pdf
- https://site-1042917.mozfiles.com/files/1042917/24107997905.pdf
- https://site-1039515.mozfiles.com/files/1039515/21002195400.pdf
- https://site-1038416.mozfiles.com/files/1038416/pevekedaj.pdf
- https://uploads.strikinglycdn.com/files/212c2a01-cb43-427a-8df8-9628b4265d96/22087213067.pdf
- https://uploads.strikinglycdn.com/files/9ac2eb88-1b21-4d4a-bcb3-53207c7fb5b0/96650712162.pdf
- https://uploads.strikinglycdn.com/files/da768e17-9cd0-419f-ae4b-5d006f307eb0/73502755995.pdf
- https://cdn.shopify.com/s/files/1/0436/6001/7814/files/xozoxowibimases.pdf
- https://cdn.shopify.com/s/files/1/0437/4278/9786/files/elite_dungeon_2_map.pdf
- https://cdn.shopify.com/s/files/1/0266/9376/3267/files/73409018768.pdf
- https://cdn.shopify.com/s/files/1/0437/8155/4325/files/constructivist_lesson_plan_for_english.pdf
- https://cdn-cms.f-static.net/uploads/4373998/normal_5f88daf229170.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f8900299690a.pdf
- https://uploads.strikinglycdn.com/files/e58f3b43-b4af-4e10-a56a-17ac3e6b80da/77120073099.pdf
- https://uploads.strikinglycdn.com/files/10980f3d-175e-47b2-8368-b5a9273f0d62/xixokokazi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1038963.mozfiles.com
- site-1040513.mozfiles.com
- site-1042917.mozfiles.com
- site-1039515.mozfiles.com
- site-1038416.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report