SUSPICIOUS — normal_5f870a8922d02.pdf
SUSPICIOUS — normal_5f870a8922d02.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b96e5816d263478bf0e0ed44ca057d9e18df2ba8aa6827ae6bcd00a34121e88d - SHA-1:
cc7ef557f8b13f196c5c65176fa7a23a8aaf5062 - MD5:
15b39fee6d6887834445f23bd02320cb - ssdeep:
768:GgGzpD3pNIQo1VDOR36xjPHYbpAGik7ILsZJ/fbOFliXLb1rGX2ArdlZDR/Pbue:TGFjpSzrs//fiwLb1rGX2AhlZdPbue - TLSH:
T19D307EF350A7EC4CBA4F6B17ADAB1059A549C78D6037AB90448C273CC4BC6FD6E10A61 - Submitted as: normal_5f870a8922d02.pdf
- File type: pdf · Size: 38164 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=the+story+of+us+westward+expansion+worksheet, https://cdn-cms.f-static.net/uploads/4366015/normal_5f86fe930552b.pdf, https://cdn-cms.f-static.net/uploads/4365567/normal_5f870935b51bf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=the+story+of+us+westward+expansion+worksheet
- https://cdn-cms.f-static.net/uploads/4366015/normal_5f86fe930552b.pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f870935b51bf.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f86fabd5fd19.pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f8709ac5b90c.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f8704565841d.pdf
- https://uploads.strikinglycdn.com/files/00331ea1-7f11-4f78-8ef4-52ddad2a27cd/jojovu.pdf
- https://uploads.strikinglycdn.com/files/c01f665a-42cb-4033-bdf2-06f55b514156/8657058244.pdf
- https://uploads.strikinglycdn.com/files/3233bcf1-cbe5-462f-af23-ef0e5d28f13e/66535605720.pdf
- https://site-1039187.mozfiles.com/files/1039187/45300438404.pdf
- https://site-1039355.mozfiles.com/files/1039355/kezusuxanuzojed.pdf
- https://site-1039290.mozfiles.com/files/1039290/84782076622.pdf
- https://site-1040426.mozfiles.com/files/1040426/60603217626.pdf
- https://uploads.strikinglycdn.com/files/8734aa40-2c60-4469-8e93-437be5bbf4df/retufegumozin.pdf
- https://uploads.strikinglycdn.com/files/834ab696-81e0-4928-9f77-a93c86e89a4a/fipafij.pdf
- https://uploads.strikinglycdn.com/files/8504d61c-a7eb-4754-8985-9bb7553af57b/76561905858.pdf
- https://cdn-cms.f-static.net/uploads/4365552/normal_5f86f7560123d.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f87078e9b3e3.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f86f444355d1.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f86ff7f5106d.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f87052517efc.pdf
- https://cdn.shopify.com/s/files/1/0496/4519/1331/files/sql_crash_course.pdf
- https://cdn.shopify.com/s/files/1/0499/3653/1614/files/which_elements_react_with_each_other.pdf
- https://cdn.shopify.com/s/files/1/0483/0720/8355/files/essentials_of_business_communication_10e_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0433/7968/7587/files/35826355972.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1039187.mozfiles.com
- site-1039355.mozfiles.com
- site-1039290.mozfiles.com
- site-1040426.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report