SUSPICIOUS — normal_5f88b8513024a.pdf
SUSPICIOUS — normal_5f88b8513024a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a4b542cfdb590788d763e0101b4696ce434002a0d029a8353ee0dd25f9d003e0 - SHA-1:
ff7a2bb34e5f63cef2dc07b2514e30b8694021aa - MD5:
9252f283bfcc4de8848d0a1c09313025 - ssdeep:
768:OgGzpDgpgAJrdnnxrC07XDwNyRvdh/oD3xdW:rGFkpBrLhdhgxdW - TLSH:
T1EF308EF710ABDE8C7E87AB436AF715552089C38C6223A75049886B6CC9BC6BD7F41470 - Submitted as: normal_5f88b8513024a.pdf
- File type: pdf · Size: 36785 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=derecho+constitucional+mexicano+comparado+fix+zamudio+pdf, https://cdn-cms.f-static.net/uploads/4368471/normal_5f888edd1eeb6.pdf, https://cdn-cms.f-static.net/uploads/4369311/normal_5f88376ec8a09.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=derecho+constitucional+mexicano+comparado+fix+zamudio+pdf
- https://cdn-cms.f-static.net/uploads/4368471/normal_5f888edd1eeb6.pdf
- https://cdn-cms.f-static.net/uploads/4369311/normal_5f88376ec8a09.pdf
- https://cdn-cms.f-static.net/uploads/4371536/normal_5f8882ba22a16.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f870baa16f66.pdf
- https://cdn-cms.f-static.net/uploads/4367019/normal_5f87711665567.pdf
- https://site-1038332.mozfiles.com/files/1038332/69150198868.pdf
- https://site-1038803.mozfiles.com/files/1038803/56961654174.pdf
- https://uploads.strikinglycdn.com/files/4778a1d7-8796-4ee3-8195-f5a416089d72/jiwokinomodevowokosed.pdf
- https://uploads.strikinglycdn.com/files/3e03ad8d-d960-4e36-9b7b-0830c981b5ef/limokojiduguzexowevunan.pdf
- https://uploads.strikinglycdn.com/files/d1ffacb8-18cd-4bfb-a4cc-7e1e09c4a1aa/90634841267.pdf
- https://site-1038872.mozfiles.com/files/1038872/kawewewuwesoj.pdf
- https://site-1038789.mozfiles.com/files/1038789/74638383656.pdf
- https://site-1038475.mozfiles.com/files/1038475/memuga.pdf
- https://site-1038963.mozfiles.com/files/1038963/97789708681.pdf
- https://site-1038782.mozfiles.com/files/1038782/zigadotelafonugaxepuzufup.pdf
- https://site-1039194.mozfiles.com/files/1039194/genupaworunija.pdf
- https://site-1043177.mozfiles.com/files/1043177/zakamefurajuker.pdf
- https://site-1048173.mozfiles.com/files/1048173/nodogulinugoxoteded.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1038332.mozfiles.com
- site-1038803.mozfiles.com
- uploads.strikinglycdn.com
- site-1038872.mozfiles.com
- site-1038789.mozfiles.com
- site-1038475.mozfiles.com
- site-1038963.mozfiles.com
- site-1038782.mozfiles.com
- site-1039194.mozfiles.com
- site-1043177.mozfiles.com
- site-1048173.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report