SUSPICIOUS — normal_5f888236617b2.pdf
SUSPICIOUS — normal_5f888236617b2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
acfd8a553c920998684fedae985439601904c7824dac65f3acabf308850a593b - SHA-1:
f986b40a333d7b4f3a3a034165fabd77f53eca80 - MD5:
9b1280da19f6424c221cc175a5741837 - ssdeep:
1536:VGF0pfldUczTa8LiTWG4sY0inmMWc0nuVtTFGSVF:oF0pNdZfmW/GinmQ0uVtxGS7 - TLSH:
T19533AEF310ABEC8D7AC69717AC9B1529A08AD78D66379760448C3B2CC4FC7BD6E10460 - Submitted as: normal_5f888236617b2.pdf
- File type: pdf · Size: 52150 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=granny+smith+full+apk+indir, https://cdn-cms.f-static.net/uploads/4365607/normal_5f87a1671baaf.pdf, https://cdn-cms.f-static.net/uploads/4366029/normal_5f875d88b79ab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=granny+smith+full+apk+indir
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f87a1671baaf.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f875d88b79ab.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f86f441342a8.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/vepulakanug.pdf
- https://pukotegifo.weebly.com/uploads/1/3/0/8/130874060/jimub.pdf
- https://cdn.shopify.com/s/files/1/0436/2040/1316/files/dr_caroline_leaf_ebooks.pdf
- https://cdn.shopify.com/s/files/1/0487/7248/1190/files/intelligence_investigation_vs_wisdom_perception.pdf
- https://cdn.shopify.com/s/files/1/0477/2226/6780/files/dd_scholar_class_5e.pdf
- https://cdn.shopify.com/s/files/1/0496/1258/7171/files/backyard_grill_3_burner_lp_propane_gas_grill_bbq.pdf
- https://cdn.shopify.com/s/files/1/0434/4178/2946/files/20413487502.pdf
- https://cdn.shopify.com/s/files/1/0496/8067/9064/files/59948951411.pdf
- https://cdn.shopify.com/s/files/1/0498/8724/8538/files/2019_fdot_index_304.pdf
- https://cdn.shopify.com/s/files/1/0486/5002/7176/files/pentair_intelliflo_2_vst_manual.pdf
- https://cdn.shopify.com/s/files/1/0483/8565/4942/files/no_one_here_gets_out_alive_jerry_hopkins.pdf
- https://cdn.shopify.com/s/files/1/0268/8083/5766/files/shade_garden_plans_zone_5.pdf
- https://cdn.shopify.com/s/files/1/0497/1593/7441/files/lowofi.pdf
- https://cdn.shopify.com/s/files/1/0501/8330/7445/files/44610071732.pdf
- https://cdn.shopify.com/s/files/1/0493/1285/8278/files/elite_dangerous_type_9_mining_build.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f8727bf67ebc.pdf
- https://cdn-cms.f-static.net/uploads/4370052/normal_5f88724b422c5.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- mojivimimujovo.weebly.com
- pukotegifo.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report