SUSPICIOUS — normal_5f8b3a706a31b.pdf
SUSPICIOUS — normal_5f8b3a706a31b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a00bbd92debed1b01e49721deded7eb3adcba4d5c5525402d40390d840e8d667 - SHA-1:
1fd220cc447be13893062512f09aa93621cca17b - MD5:
a6b1b1e00abfffed65630b1bba829e45 - ssdeep:
768:DgGzpDppr7+Y303wIRid/bxYXTScG3n9ebucikrXS2Fki+S0SHJI0C:8GFlprrYon9IRiOXSKI0C - TLSH:
T16E307DF300A3EC8C7A4B6B13AAFB0559658EC38C6036D360948C672DC0BC5EE7E10A51 - Submitted as: normal_5f8b3a706a31b.pdf
- File type: pdf · Size: 38814 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=cultura+general+para+dummies+pdf+descargar+gratis, https://cdn-cms.f-static.net/uploads/4377902/normal_5f8a944e334a3.pdf, https://cdn-cms.f-static.net/uploads/4367940/normal_5f8994e573d6c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=cultura+general+para+dummies+pdf+descargar+gratis
- https://cdn-cms.f-static.net/uploads/4377902/normal_5f8a944e334a3.pdf
- https://cdn-cms.f-static.net/uploads/4367940/normal_5f8994e573d6c.pdf
- https://cdn-cms.f-static.net/uploads/4370063/normal_5f8905c4797cc.pdf
- https://cdn.shopify.com/s/files/1/0432/0120/0289/files/60173125653.pdf
- https://cdn.shopify.com/s/files/1/0485/2478/7867/files/pufutadobivikake.pdf
- https://cdn.shopify.com/s/files/1/0499/1477/3672/files/gavusegugox.pdf
- https://cdn-cms.f-static.net/uploads/4371799/normal_5f8a678d84444.pdf
- https://cdn-cms.f-static.net/uploads/4366401/normal_5f8759a1c2f3c.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f87300e82600.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f8b2058a713a.pdf
- https://uploads.strikinglycdn.com/files/41371ed4-f9f1-4fa2-8014-2cf7791a664b/xikitumakulo.pdf
- https://uploads.strikinglycdn.com/files/91f9e613-5c2d-42c9-ae5d-57b847b07563/livevajadaferefebilupog.pdf
- https://uploads.strikinglycdn.com/files/347e48ff-3556-4738-b303-d7b7bbec4dd6/pisitodosekelewobebe.pdf
- https://uploads.strikinglycdn.com/files/1203a824-d6ae-4cbd-84d2-5315759a5e27/raxewubake.pdf
- https://uploads.strikinglycdn.com/files/7fafbb2d-9a2e-4c9b-8a9d-b848074134b5/95199613599.pdf
- https://uploads.strikinglycdn.com/files/bb2cfd80-40e9-4bc7-8267-27f0d8d0b6fb/dadoxu.pdf
- https://uploads.strikinglycdn.com/files/a16180dd-bb27-4e6a-97d1-25d352f4aa33/sanelovobifo.pdf
- https://uploads.strikinglycdn.com/files/d4c3b96c-48f3-4ac9-9074-595f3c943f0b/38871650774.pdf
- https://uploads.strikinglycdn.com/files/f7fe565e-4aa2-4d32-9032-2b6ed5056c41/the_wrath_of_cain.pdf
- https://uploads.strikinglycdn.com/files/4364d0e6-00a7-4df7-8c8a-c42c43ab86b8/60036141177.pdf
- https://uploads.strikinglycdn.com/files/5d2fedb7-de98-4dd5-85f0-06ca75f51d3f/52658443449.pdf
- https://uploads.strikinglycdn.com/files/efa58157-36f3-491e-8192-4450700f09b5/5706763569.pdf
- https://uploads.strikinglycdn.com/files/a4bbbfd2-71f2-4cc9-9cad-5d0550b24fbb/taduzafezuzamaruxos.pdf
- https://uploads.strikinglycdn.com/files/f3475d3f-23c8-4276-b81c-1b0d86952880/lidovufunixag.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report