SUSPICIOUS — normal_5f8b112ebd35d.pdf
SUSPICIOUS — normal_5f8b112ebd35d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
86d0944ef09c47b4a9994a16dfe449991028f388c4ecc387c4a16342108752f1 - SHA-1:
9ed611d9b7762754fa3889191c76b739796fcf59 - MD5:
784d105eb7f33b270376f7105d38d82b - ssdeep:
768:2gGzpDXpNT+c5SbUIyIDqtP6GO1pJ0c6gkTAxwwRyMnc2lnCp6f1+:jGFrpWfJ0c6gemaklnCp6f1+ - TLSH:
T10C329EF390ABDC4C7E87AB07BDA32556A485D38862329B90458C772CD47CAED7F10960 - Submitted as: normal_5f8b112ebd35d.pdf
- File type: pdf · Size: 46644 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=pulsar+digisight+ultra+n455+manual, https://cdn-cms.f-static.net/uploads/4367648/normal_5f8a9b4594c4e.pdf, https://cdn-cms.f-static.net/uploads/4369784/normal_5f8859fa29a46.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=pulsar+digisight+ultra+n455+manual
- https://cdn-cms.f-static.net/uploads/4367648/normal_5f8a9b4594c4e.pdf
- https://cdn-cms.f-static.net/uploads/4369784/normal_5f8859fa29a46.pdf
- https://cdn-cms.f-static.net/uploads/4367959/normal_5f8a266746d5c.pdf
- https://cdn-cms.f-static.net/uploads/4369651/normal_5f8852b8cf526.pdf
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f88d88a117bc.pdf
- https://cdn-cms.f-static.net/uploads/4368956/normal_5f87982f3a2e8.pdf
- https://cdn-cms.f-static.net/uploads/4370744/normal_5f88be2d54c91.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f878697c868a.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f8954f596bc7.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f874e8f35be1.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f8a092cd52f1.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/5747744.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/3d7af44.pdf
- https://goduvozimaku.weebly.com/uploads/1/3/1/3/131380582/1937686.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/lexenumijosowemakaz.pdf
- https://dofazodasi.weebly.com/uploads/1/3/0/8/130873943/janom_mulefof.pdf
- https://cdn.shopify.com/s/files/1/0438/5662/5829/files/ash_2020_registration.pdf
- https://cdn.shopify.com/s/files/1/0501/0957/9429/files/life_under_the_sea_word_whizzle_answers.pdf
- https://uploads.strikinglycdn.com/files/ea429763-d8c3-4f7e-993b-571174c0f20e/judujave.pdf
- https://uploads.strikinglycdn.com/files/fa722e98-e83a-4fe7-9390-ee120c3c28fa/69620187974.pdf
- https://uploads.strikinglycdn.com/files/2f29cd09-bffe-499e-8abe-55dd50d63cde/zobukajoteleburaz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- sepikupi.weebly.com
- zoveponezewuda.weebly.com
- goduvozimaku.weebly.com
- viweposedijul.weebly.com
- dofazodasi.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report