SUSPICIOUS — normal_5f86ffdec8f1f.pdf
SUSPICIOUS — normal_5f86ffdec8f1f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c513f38d3bf2fc94ed1ae8487fbae6413528ed6bae4ee3baf6d7569bf57e4dac - SHA-1:
231b6969326ed612f4571232f99695daac366e76 - MD5:
15aba6c3b756211d6c548080fb7a7a11 - ssdeep:
768:WgGzpDgfpJq0DXkKD1Eo4+SXIvSjF44JpQuLEBN+FqCQLwNug59GScJ4:DGFGpIIXkogjFdJp2BN+F+c4g5sScJ4 - TLSH:
T1CF34AEF31167EE8C6A8B57836EE712597485C28D717793A014887B2CC87CBBD2F10A51 - Submitted as: normal_5f86ffdec8f1f.pdf
- File type: pdf · Size: 53927 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=warlock+of+the+magus+world+pdf+espa%25C3%25B1ol, https://site-1042867.mozfiles.com/files/1042867/xometom.pdf, https://site-1038341.mozfiles.com/files/1038341/xilupasedi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=warlock+of+the+magus+world+pdf+espa%25C3%25B1ol
- https://site-1042867.mozfiles.com/files/1042867/xometom.pdf
- https://site-1038341.mozfiles.com/files/1038341/xilupasedi.pdf
- https://site-1043937.mozfiles.com/files/1043937/nomodudi.pdf
- https://site-1039444.mozfiles.com/files/1039444/tonusomowep.pdf
- https://site-1036661.mozfiles.com/files/1036661/6287701491.pdf
- https://uploads.strikinglycdn.com/files/2ef855b0-1484-48d1-acc2-e91bc5c8c153/roxip.pdf
- https://uploads.strikinglycdn.com/files/fac028bf-57b3-4400-8355-023b5bee071f/58705712742.pdf
- https://uploads.strikinglycdn.com/files/721a87a1-3dc0-46b2-89ca-a84eef966712/47785302092.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f86f9cae2c17.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f86f553ac920.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f86f58d3b3c8.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f86f96fdddad.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f86f895d47b3.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/debizikirapanas.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/mukobuf.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/bosilo_ginasesif.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/059d55fbff3.pdf
- https://uploads.strikinglycdn.com/files/a9881d92-6d4a-458d-852c-891ba4dbabe0/22663080648.pdf
- https://uploads.strikinglycdn.com/files/266ef3e4-7e5b-4a90-9587-ab2c93c09e7a/pakaxefof.pdf
- https://cdn.shopify.com/s/files/1/0501/7642/6144/files/vodupugekuguzo.pdf
- https://cdn.shopify.com/s/files/1/0430/3847/4393/files/mw2_emblems_unlock_guide.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- site-1042867.mozfiles.com
- site-1038341.mozfiles.com
- site-1043937.mozfiles.com
- site-1039444.mozfiles.com
- site-1036661.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- vuxozajuje.weebly.com
- zoxuzuxebexot.weebly.com
- mogilifus.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report