SUSPICIOUS — normal_5f8a56ae684d6.pdf
SUSPICIOUS — normal_5f8a56ae684d6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8dec325f2a378aacd32164b54eaa9a30f5dc975b60e09ddfc4f82f1d2c1bf3dd - SHA-1:
f95722363667d62eaa935e5684d56ae5a98c10e0 - MD5:
b3da0f2b9d258ba068d06887a6ed37a2 - ssdeep:
1536:yGFEpY8Rwn3opRmL0ri9nFNu4c8Zwqf6:rFEpY8vp10FrYh - TLSH:
T12A339EF360A7ED8D7AC7DB03ACA70569544EE64862369B6054CC372CC4FC1BDAE10891 - Submitted as: normal_5f8a56ae684d6.pdf
- File type: pdf · Size: 49351 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=unstoppable+god+piano+sheet+music+pdf, https://cdn-cms.f-static.net/uploads/4368745/normal_5f88d821bce02.pdf, https://cdn-cms.f-static.net/uploads/4367940/normal_5f8a21fa461c9.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=unstoppable+god+piano+sheet+music+pdf
- https://cdn-cms.f-static.net/uploads/4368745/normal_5f88d821bce02.pdf
- https://cdn-cms.f-static.net/uploads/4367940/normal_5f8a21fa461c9.pdf
- https://cdn-cms.f-static.net/uploads/4369660/normal_5f88dcfa70406.pdf
- https://cdn-cms.f-static.net/uploads/4374364/normal_5f8a04f5b630d.pdf
- https://cdn-cms.f-static.net/uploads/4374857/normal_5f8a155a3a35f.pdf
- https://uploads.strikinglycdn.com/files/0ead7537-1255-4d44-809a-d06353f1f84c/37981738114.pdf
- https://cdn.shopify.com/s/files/1/0435/7275/6648/files/little_tikes_playground_climber.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/32545943577.pdf
- https://cdn.shopify.com/s/files/1/0482/1811/2154/files/mukixebu.pdf
- https://cdn.shopify.com/s/files/1/0498/8646/2106/files/pantip.pdf
- https://cdn.shopify.com/s/files/1/0268/7628/1025/files/sobonaweg.pdf
- https://cdn.shopify.com/s/files/1/0430/3876/9303/files/wabagexob.pdf
- https://cdn.shopify.com/s/files/1/0501/8307/8048/files/pofut.pdf
- https://cdn.shopify.com/s/files/1/0430/1435/7151/files/lee_differential_geometry.pdf
- https://cdn.shopify.com/s/files/1/0427/7246/3772/files/torunikegiwokobasamogis.pdf
- https://cdn.shopify.com/s/files/1/0431/3881/0023/files/zer0_skill_tree.pdf
- https://uploads.strikinglycdn.com/files/02c103d2-f543-4a34-afa6-d66410601c42/48481580941.pdf
- https://uploads.strikinglycdn.com/files/3a6107da-f6a0-4206-8ee7-d43270e0ebad/javoxaberisuv.pdf
- https://uploads.strikinglycdn.com/files/a299bfc2-923a-4577-8c0e-63ce305312fa/wasuxusosawirutunifunodo.pdf
- https://uploads.strikinglycdn.com/files/45e9556b-c229-42aa-b9bb-548050fbe95f/3028604632.pdf
- https://uploads.strikinglycdn.com/files/e014f678-142c-4dd1-94b0-31b01a6fdd53/laredodevilivurevefazowa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report