SUSPICIOUS — normal_5f88c294e046c.pdf
SUSPICIOUS — normal_5f88c294e046c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
bdfd6e3391607a95e34feba4dd1cc5caf1d751462826a4a12f7deef004bcd155 - SHA-1:
cddb9472f1f626ef4c30e09b4e6afcf6fcb156a5 - MD5:
ec3655b35a192adbe932096a7b0273cb - ssdeep:
1536:GGFue4k8/G0yZMCVPuSLQFEtotn0Pbe2g9CVt+:fFueABy7VWSLQFEtotn0qTAW - TLSH:
T15337BFF35197DC8C328B6F039DBB1598B19AD7491136DB9019C8BB6CC4BC6BD6E11A00 - Submitted as: normal_5f88c294e046c.pdf
- File type: pdf · Size: 70572 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=kraft+mac+n+cheese+microwave+instructions, https://uploads.strikinglycdn.com/files/a7a18d69-4c07-40b0-88cd-91a0507bc830/13485436921.pdf, https://uploads.strikinglycdn.com/files/d40eb801-c1c7-406e-870d-8c904607c302/rumarotozes.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=kraft+mac+n+cheese+microwave+instructions
- https://uploads.strikinglycdn.com/files/a7a18d69-4c07-40b0-88cd-91a0507bc830/13485436921.pdf
- https://uploads.strikinglycdn.com/files/d40eb801-c1c7-406e-870d-8c904607c302/rumarotozes.pdf
- https://uploads.strikinglycdn.com/files/49e88516-1d79-4fc8-81c3-3026243ef0e8/lunutogonoxigepamiki.pdf
- https://uploads.strikinglycdn.com/files/baecdba9-ee5e-4788-9b30-d9d1356d5822/14992741522.pdf
- https://uploads.strikinglycdn.com/files/3f204c26-5279-4854-b65f-f8944510d9f4/duramegoxutefi.pdf
- https://uploads.strikinglycdn.com/files/9e8d0bfe-9f1a-4126-a7a6-0edbddffc730/29182246411.pdf
- https://uploads.strikinglycdn.com/files/80c20dd6-33af-4492-b524-132276401c1b/53516439266.pdf
- https://cdn-cms.f-static.net/uploads/4370078/normal_5f88978b8a81e.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f8820a297470.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f8720f903ccd.pdf
- https://cdn-cms.f-static.net/uploads/4369331/normal_5f88208e26f87.pdf
- https://uploads.strikinglycdn.com/files/a3f9ae41-d68e-4d1b-b016-2652de64b88c/72021479104.pdf
- https://uploads.strikinglycdn.com/files/89b32eba-00ae-4547-9b87-87314bd9c787/zonapodamipoz.pdf
- https://uploads.strikinglycdn.com/files/22a762aa-7530-4466-900d-fd12800abbe4/20658450948.pdf
- https://site-1039515.mozfiles.com/files/1039515/natusulerisilisulisub.pdf
- https://site-1038573.mozfiles.com/files/1038573/nipaxojolagixizeto.pdf
- https://site-1037885.mozfiles.com/files/1037885/28102350889.pdf
- https://cdn.shopify.com/s/files/1/0434/1841/9349/files/60503540074.pdf
- https://cdn.shopify.com/s/files/1/0500/1222/5694/files/nimikefeji.pdf
- https://cdn.shopify.com/s/files/1/0430/6488/5397/files/nefiwozoguxalaburotesokan.pdf
- https://cdn.shopify.com/s/files/1/0495/9915/2292/files/ejercicios_para_resolver_de_operaciones_combinadas_con_numeros_reales.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1039515.mozfiles.com
- site-1038573.mozfiles.com
- site-1037885.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report