SUSPICIOUS — normal_5f8a935104dc4.pdf
SUSPICIOUS — normal_5f8a935104dc4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b8aaafa0ddbdf41d8efc96fd41f2d8c64de85a0d2f4c62adeea4b1ef888394f2 - SHA-1:
21d1c9350a5e42d5bca89bb03d045e0881c823d3 - MD5:
9607b3e3d95adc4efbe1071cb4c20a42 - ssdeep:
768:JkgGzpDip+0iuODhXr9a7B24rBi8FZDWVim276Lax5TQ5TgoKPMhB6BRYZtRolCl:vGFeppDWVim276a3TQ9CPMhBcctRoAl - TLSH:
T186329EF750A7FD4C7ACE9B13AEAB1059608AD38C613397A054882B2CD4BC5ED7F10564 - Submitted as: normal_5f8a935104dc4.pdf
- File type: pdf · Size: 46095 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=download+software+android+lollipop+5.1, https://uploads.strikinglycdn.com/files/a30364e6-f232-4b76-867a-424240ec23bc/lie_detector_test_app.pdf, https://uploads.strikinglycdn.com/files/643a1091-49aa-47d2-8e8d-fdc3faeea0ed/92356102152.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=download+software+android+lollipop+5.1
- https://uploads.strikinglycdn.com/files/a30364e6-f232-4b76-867a-424240ec23bc/lie_detector_test_app.pdf
- https://uploads.strikinglycdn.com/files/643a1091-49aa-47d2-8e8d-fdc3faeea0ed/92356102152.pdf
- https://uploads.strikinglycdn.com/files/a25155f3-c65a-41d0-a85c-dc52726b3f43/zidibevariketi.pdf
- https://uploads.strikinglycdn.com/files/5ebb0f93-29eb-4a7e-b78c-ca2475be3b3f/46736717041.pdf
- https://cdn-cms.f-static.net/uploads/4374976/normal_5f8917a2b7b7f.pdf
- https://cdn-cms.f-static.net/uploads/4377401/normal_5f8a90bc85bf7.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f87207fbb0c1.pdf
- https://uploads.strikinglycdn.com/files/407565ee-3e22-4eab-b938-72670c911c0c/mitanapebivawatoli.pdf
- https://uploads.strikinglycdn.com/files/28665852-8dfa-4908-9f2c-5a311ff5b489/51795900581.pdf
- https://cdn.shopify.com/s/files/1/0480/1475/3951/files/24362517195.pdf
- https://cdn.shopify.com/s/files/1/0500/3047/7472/files/beetlejuice_musical_bootleg.pdf
- https://cdn.shopify.com/s/files/1/0435/2416/1704/files/all_dyes_in_minecraft_bedrock.pdf
- https://cdn.shopify.com/s/files/1/0496/2392/4889/files/parse_json_android_volley.pdf
- https://cdn.shopify.com/s/files/1/0497/6050/1921/files/tuberculosis_meningea_en_nios.pdf
- https://cdn.shopify.com/s/files/1/0427/4143/2487/files/30052635942.pdf
- https://cdn.shopify.com/s/files/1/0496/0469/0069/files/acta_de_reuniones_pie.pdf
- https://cdn.shopify.com/s/files/1/0483/5092/0855/files/county_assessor_alameda_voter_guide.pdf
- https://cdn.shopify.com/s/files/1/0268/6956/3575/files/rawazovozomis.pdf
- https://cdn-cms.f-static.net/uploads/4369519/normal_5f895a403a0d6.pdf
- https://cdn-cms.f-static.net/uploads/4366042/normal_5f890cd349603.pdf
- https://cdn-cms.f-static.net/uploads/4366652/normal_5f8a5d7058e35.pdf
- https://cdn-cms.f-static.net/uploads/4367947/normal_5f884f06897dd.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- s0.ch
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report