SUSPICIOUS — normal_5f99c0419a3f2.pdf
SUSPICIOUS — normal_5f99c0419a3f2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c6eacf88cd6f9d231223ec576042a205e8b1b06ce546388ae91499a739eb2da6 - SHA-1:
41f068c3fee0b07cb9f96e9be190cb08707ef171 - MD5:
dfc648d41cb8f68d378462e88fa10bb5 - ssdeep:
768:CgGzpDoFisS7G9maTLm2/2WWllS7LgG+xEjSz:fGFMs3yEMUlisG+xEjSz - TLSH:
T12B307DF350A3ED8C7A8E9F43EEBA21595185878DA1339A6058D8673CC47C6BE6F00C50 - Submitted as: normal_5f99c0419a3f2.pdf
- File type: pdf · Size: 38326 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=kayak+dry+suit+uk, https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/737298.pdf, https://cdn.shopify.com/s/files/1/0429/1526/6723/files/noxukerijapoxuridawus.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=kayak+dry+suit+uk
- https://s3.amazonaws.com/tifuwuw/82926468813.pdf
- https://s3.amazonaws.com/wefadep/33784066376.pdf
- https://s3.amazonaws.com/miwolezedubujoz/90727316696.pdf
- https://s3.amazonaws.com/piwupevivotixi/vocabulary_exercises_for_pre-_intermediate_students.pdf
- https://s3.amazonaws.com/fasanag/properties_of_benzoic_acid.pdf
- https://s3.amazonaws.com/zetare/55638469955.pdf
- https://s3.amazonaws.com/loxopudizus/nasatapalonij.pdf
- https://s3.amazonaws.com/tojabixefova/psychology_101_study_guide.pdf
- https://s3.amazonaws.com/gebaxovudofe/98664009633.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/737298.pdf
- https://s3.amazonaws.com/sinadi/labour_law_manual.pdf
- https://cdn.shopify.com/s/files/1/0429/1526/6723/files/noxukerijapoxuridawus.pdf
- https://s3.amazonaws.com/dinisemowoge/kijusilukexunuruluvirimo.pdf
- https://rizidapovo.weebly.com/uploads/1/3/4/3/134316848/xidagu-nalavilagozi-wirosokimugov.pdf
- https://s3.amazonaws.com/desenaz/favola_di_amore_e_psiche.pdf
- https://s3.amazonaws.com/zetare/bailey_and_love_latest_edition_free.pdf
- https://gavawujag.weebly.com/uploads/1/3/4/3/134370084/ruduzekidiredaduxo.pdf
- https://cdn.shopify.com/s/files/1/0266/8150/8022/files/quadratic_equation_examples_and_answers.pdf
- https://cdn.shopify.com/s/files/1/0438/3100/1238/files/transmigration_of_souls_christianity.pdf
- https://s3.amazonaws.com/xaliwalufoguni/56419451506.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- tejigenunonim.weebly.com
- cdn.shopify.com
- rizidapovo.weebly.com
- gavawujag.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report