SUSPICIOUS — normal_5f98bf92359ca.pdf
SUSPICIOUS — normal_5f98bf92359ca.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
843dcc7ccf173c5a309e00c5bd05496e47d8b838de4231999e9c09fde0203d9e - SHA-1:
57ca8675b974bfb6b19c9661bd5cfa4fb8b41fd8 - MD5:
e839cc6a62ca868ca0c282ae65ef8eb2 - ssdeep:
1536:SGFPpCvYEpdLSR3lhIC+MLtnPR5WXRuShECxe4:LFPp6jLE1hI0PRURuShTxl - TLSH:
T10733AEF3108BEC4C7A878B47ACEA1059654DC78DB132EBA15988371CE47C67DBE14A60 - Submitted as: normal_5f98bf92359ca.pdf
- File type: pdf · Size: 51320 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=ff14+pugilist+guide, https://cdn-cms.f-static.net/uploads/4419433/normal_5f98ae95e1ce3.pdf, https://cdn-cms.f-static.net/uploads/4378405/normal_5f987684ed7fb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=ff14+pugilist+guide
- https://cdn-cms.f-static.net/uploads/4419433/normal_5f98ae95e1ce3.pdf
- https://cdn-cms.f-static.net/uploads/4378405/normal_5f987684ed7fb.pdf
- https://cdn-cms.f-static.net/uploads/4383131/normal_5f96e0d61ff59.pdf
- https://cdn-cms.f-static.net/uploads/4405904/normal_5f920a46df518.pdf
- https://cdn-cms.f-static.net/uploads/4382793/normal_5f8ed1f633e49.pdf
- https://cdn.shopify.com/s/files/1/0486/2115/8558/files/xodifisowijusu.pdf
- https://cdn.shopify.com/s/files/1/0463/3185/5003/files/megozur.pdf
- https://cdn.shopify.com/s/files/1/0434/0416/5285/files/terk_amplified_indoor_flat_hdtv_antenna.pdf
- https://noxetetejiv.weebly.com/uploads/1/3/4/3/134391164/31cb63b8.pdf
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/manilumaj.pdf
- https://garagagu.weebly.com/uploads/1/3/4/3/134364865/2563302.pdf
- https://fenivubad.weebly.com/uploads/1/3/4/4/134482284/4970263.pdf
- https://sitawixabebel.weebly.com/uploads/1/3/4/3/134319036/jilimoturoko.pdf
- https://cdn.shopify.com/s/files/1/0268/7513/4135/files/91113997752.pdf
- https://cdn.shopify.com/s/files/1/0484/3064/5416/files/wasp_sting_removal_guide.pdf
- https://cdn-cms.f-static.net/uploads/4394068/normal_5f8effbc88dbb.pdf
- https://cdn-cms.f-static.net/uploads/4376598/normal_5f8b6bd4dd193.pdf
- https://cdn-cms.f-static.net/uploads/4406169/normal_5f95690deddda.pdf
- https://cdn.shopify.com/s/files/1/0499/4947/4971/files/the_boy_who_cried_wolf_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0266/9723/6650/files/cell_structure_and_function_crossword_puzzle_answers.pdf
- https://cdn.shopify.com/s/files/1/0498/0408/3354/files/ap_photography_concentration.pdf
- https://cdn.shopify.com/s/files/1/0500/0042/9206/files/prime_video_apk_fire_tv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- noxetetejiv.weebly.com
- wefamojugibe.weebly.com
- garagagu.weebly.com
- fenivubad.weebly.com
- sitawixabebel.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report