SUSPICIOUS — normal_5f8723d995469.pdf
SUSPICIOUS — normal_5f8723d995469.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
bffdd66c1409da8bfe1b29011162abbf56b769149f3d4f8addf56a142ccd6630 - SHA-1:
f0e355f0cdd7d45e136cf57c24898da03970a8d7 - MD5:
9184a73fc6a2d6f5f65a6303b630feab - ssdeep:
768:KgGzpDIpeWqXM2ejm+lX/SjX+6KKEdbTtDaNSXn6XqzpKL5CRymTacwUcU76G:XGFUpNX/S7+7dTtGslg2yBct76G - TLSH:
T11D32AEF35063ED4C7A8A5B07AEAE105A944DD78D6132E7A044C8673CD9BC6FD6F10610 - Submitted as: normal_5f8723d995469.pdf
- File type: pdf · Size: 45975 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=total+file+commander+pro+apk, https://site-1043485.mozfiles.com/files/1043485/87325475443.pdf, https://site-1039784.mozfiles.com/files/1039784/jexodupukoki.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=total+file+commander+pro+apk
- https://site-1043485.mozfiles.com/files/1043485/87325475443.pdf
- https://site-1039784.mozfiles.com/files/1039784/jexodupukoki.pdf
- https://site-1043047.mozfiles.com/files/1043047/83324064728.pdf
- https://cdn.shopify.com/s/files/1/0430/7622/3129/files/fomelijori.pdf
- https://cdn.shopify.com/s/files/1/0266/9392/7081/files/art_analysis_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0433/7480/5148/files/kegunukufexuzunu.pdf
- https://cdn.shopify.com/s/files/1/0481/9632/1432/files/95691575050.pdf
- https://site-1039270.mozfiles.com/files/1039270/18934435860.pdf
- https://site-1040571.mozfiles.com/files/1040571/31657232315.pdf
- https://site-1040888.mozfiles.com/files/1040888/nuvejisovagefavafipe.pdf
- https://site-1038844.mozfiles.com/files/1038844/dibijopanotokirod.pdf
- https://cdn.shopify.com/s/files/1/0499/9407/2214/files/white_crested_black_polish_chicken.pdf
- https://cdn.shopify.com/s/files/1/0486/1889/7573/files/indian_food_northwest_arkansas.pdf
- https://cdn.shopify.com/s/files/1/0503/6366/2496/files/bobby_bones_net_worth.pdf
- https://uploads.strikinglycdn.com/files/26f3e4d2-9ad9-4fa5-bdbe-1f663ddea4b4/8712993564.pdf
- https://uploads.strikinglycdn.com/files/680b9178-23dd-4ab5-a3a8-f672cb475634/pojajazokaxonemuku.pdf
- https://uploads.strikinglycdn.com/files/f58d183a-06ab-4202-8d0e-c6876b7c518f/pijomatuxutowefuxagami.pdf
- https://uploads.strikinglycdn.com/files/adc25099-067e-44b4-ac72-5e286c588cb3/mowiw.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f872305b3198.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f4e02b808.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f871bf84d2a1.pdf
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f8717687e8ee.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- site-1043485.mozfiles.com
- site-1039784.mozfiles.com
- site-1043047.mozfiles.com
- cdn.shopify.com
- site-1039270.mozfiles.com
- site-1040571.mozfiles.com
- site-1040888.mozfiles.com
- site-1038844.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.ghisler.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report