SUSPICIOUS — normal_5f8acd95acf13.pdf
SUSPICIOUS — normal_5f8acd95acf13.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a0143292dc329170886819ae8b0e433a59a6c4c0aac8984a2f06a39750ad2f64 - SHA-1:
0507f52d2fba7155fc1b23480e996bdbb5dc5c39 - MD5:
10283e4f119b29eb3ac5f9d921e78b68 - ssdeep:
768:agGzpDeptDllqglgF2fbA4kypW+FRRflkh3Jqbak4qsI7wcF+rv9B6np:HGFyptD7qFsRIh3JqbpsIBF+rL6np - TLSH:
T1BD328EF350A7EE4C7A8B9B036EEA119D504AD78CA132A764448C773DC5BC2BD7E40960 - Submitted as: normal_5f8acd95acf13.pdf
- File type: pdf · Size: 43355 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=add+fraction+unlike+denominators+worksheet, https://uploads.strikinglycdn.com/files/f2ba02f7-b056-48e5-b90d-fd24b6050728/41701024638.pdf, https://uploads.strikinglycdn.com/files/b5f9f152-e250-4d82-bae9-b6cf0ba73014/hydroforming_of_sheet_metal.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=add+fraction+unlike+denominators+worksheet
- https://uploads.strikinglycdn.com/files/f2ba02f7-b056-48e5-b90d-fd24b6050728/41701024638.pdf
- https://uploads.strikinglycdn.com/files/b5f9f152-e250-4d82-bae9-b6cf0ba73014/hydroforming_of_sheet_metal.pdf
- https://uploads.strikinglycdn.com/files/edb6bcc5-dab4-4c60-a7c2-a5b0f1ac88d4/bemopevuwu.pdf
- https://uploads.strikinglycdn.com/files/55402eab-1958-49ee-8ad5-0b214133e832/20583851420.pdf
- https://uploads.strikinglycdn.com/files/685784e5-971d-401c-826f-67d1b94ee617/15372078274.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f870479838f5.pdf
- https://cdn-cms.f-static.net/uploads/4371783/normal_5f89d537ce933.pdf
- https://cdn.shopify.com/s/files/1/0486/8059/9702/files/66200980066.pdf
- https://cdn.shopify.com/s/files/1/0432/5706/9736/files/43212518849.pdf
- https://cdn.shopify.com/s/files/1/0477/3901/1228/files/fuxagitipevapat.pdf
- https://cdn.shopify.com/s/files/1/0434/7609/1045/files/limososewurex.pdf
- https://purolejomi.weebly.com/uploads/1/3/0/7/130776639/9863192.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/7114ee1.pdf
- https://porelananov.weebly.com/uploads/1/3/0/7/130775759/xaruvafuxabapurom.pdf
- https://varipejat.weebly.com/uploads/1/3/0/7/130739080/dfb1fe63.pdf
- https://uploads.strikinglycdn.com/files/ff0f6489-34c1-48f8-a63c-db98b2a0d112/5410752857.pdf
- https://uploads.strikinglycdn.com/files/448f02a0-b0d7-4ba9-8828-676b5be33274/85745006674.pdf
- https://uploads.strikinglycdn.com/files/eb2e59eb-afb4-4a43-b0cf-0c542935add0/wisanefujo.pdf
- https://uploads.strikinglycdn.com/files/0572acd9-d809-4c61-b6c6-e58df15d8518/wefakanisegevutinituv.pdf
- https://uploads.strikinglycdn.com/files/24adf41c-45e0-4f69-a9e2-f590583443a1/36410705219.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- purolejomi.weebly.com
- juragubiv.weebly.com
- porelananov.weebly.com
- varipejat.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report