SUSPICIOUS — normal_5f870aabda91e.pdf
SUSPICIOUS — normal_5f870aabda91e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
7d6411577bc3f3b094b60e67813ea0cc262f8dce8e4533435e127ee4ce823696 - SHA-1:
05965b0aa0ed621507b0298a61ff2febace419c9 - MD5:
866267edc08f4b9cf1d82cebb62540f7 - ssdeep:
768:ZgGzpDJpuRBtMBYFk1/UU5Pmn3gmRzUyc5NaDL1/AqVle/vaMgZilYOiZI:aGFFpmhU1m3gmRzUyA0BpVle3a3Z/OiS - TLSH:
T14D327DF311A7FD8C794B6F07ADA6119D548AC78D5133DBA04488772DC0BCABD2E01A60 - Submitted as: normal_5f870aabda91e.pdf
- File type: pdf · Size: 44585 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=crafting+skill+guide+rs3, https://cdn-cms.f-static.net/uploads/4366040/normal_5f86f9e3b9cf2.pdf, https://cdn-cms.f-static.net/uploads/4366024/normal_5f86f61212da2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=crafting+skill+guide+rs3
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f86f9e3b9cf2.pdf
- https://cdn-cms.f-static.net/uploads/4366024/normal_5f86f61212da2.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f86f42213348.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f8708ecdd34b.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/8536469.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/7885719.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/domovodibaposix.pdf
- https://site-1038674.mozfiles.com/files/1038674/56264064190.pdf
- https://site-1039179.mozfiles.com/files/1039179/mifunerozopofatuk.pdf
- https://site-1043169.mozfiles.com/files/1043169/94553712304.pdf
- https://site-1039355.mozfiles.com/files/1039355/walegidor.pdf
- https://site-1041688.mozfiles.com/files/1041688/sekokekinafumunimer.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f8705fc4f8f8.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f8709936604b.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f86f84941a1d.pdf
- https://uploads.strikinglycdn.com/files/108824bf-cc6d-4f15-af7b-c80bc2818ad1/85720421583.pdf
- https://uploads.strikinglycdn.com/files/81c3fbd7-f5fd-4ccf-9732-e5c644b1f923/56025817681.pdf
- https://uploads.strikinglycdn.com/files/d33e9dea-fd24-4dbf-b200-ce0be41a2448/91212174688.pdf
- https://uploads.strikinglycdn.com/files/292c66c6-4af1-4ca2-8fbc-41a6d83ac11c/gaxaxojeximixu.pdf
- https://uploads.strikinglycdn.com/files/be9ad858-a446-4d31-97cc-a352f0371978/dibaxotivuberufanejuzav.pdf
- https://uploads.strikinglycdn.com/files/1eade2c1-7b5a-4571-8ada-6174dc5c539b/bebawu.pdf
- https://uploads.strikinglycdn.com/files/28863041-403a-4f6f-aea9-98abc6990c82/zegopukibojifoxeni.pdf
- https://uploads.strikinglycdn.com/files/a419eca7-2514-49f3-98f1-ac488515bb48/8223898996.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- jakedekokobara.weebly.com
- keniwuki.weebly.com
- guwomenod.weebly.com
- site-1038674.mozfiles.com
- site-1039179.mozfiles.com
- site-1043169.mozfiles.com
- site-1039355.mozfiles.com
- site-1041688.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report