SUSPICIOUS — normal_5f9712488faf2.pdf
SUSPICIOUS — normal_5f9712488faf2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c8c0fc090b2ee23f9399942db7b04a58334da4b889d956015daa598d49a1891d - SHA-1:
3fced8c89f877dce1bd68e506b3d1230ec756ca1 - MD5:
9a03a9f20c6b2d4dd6147d243640ae5d - ssdeep:
1536:9GF1pZAyENz0jlR28i1cTEhyEdZDX+0S00h/yLtCx:AF1pZjuqu1coVTDXY00h/qtc - TLSH:
T1F536CEF304A3ED8C7E8B5F83ADEB16996589C78DA12BE764458C762CC06C1ED7E10160 - Submitted as: normal_5f9712488faf2.pdf
- File type: pdf · Size: 65664 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=priest+buff+macro+classic, https://cdn.shopify.com/s/files/1/0430/8497/2183/files/hp_pavilion_22cwa_best_buy.pdf, https://cdn.shopify.com/s/files/1/0501/0279/6442/files/73885530900.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=priest+buff+macro+classic
- https://cdn.shopify.com/s/files/1/0430/8497/2183/files/hp_pavilion_22cwa_best_buy.pdf
- https://cdn.shopify.com/s/files/1/0501/0279/6442/files/73885530900.pdf
- https://cdn.shopify.com/s/files/1/0437/1090/6519/files/bepelonuzema.pdf
- https://cdn.shopify.com/s/files/1/0432/5031/9517/files/word_problems_with_variables_on_both_sides_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0502/9406/3269/files/lafuxopuni.pdf
- https://uploads.strikinglycdn.com/files/b75225f8-3251-42e4-b4d4-67434d952c1d/tufifaku.pdf
- https://uploads.strikinglycdn.com/files/0799b5dd-67b9-4fd8-ad4f-c49a4a77b4a4/ponajurotixaviwazuralu.pdf
- https://uploads.strikinglycdn.com/files/05548aec-d54c-4ddf-806a-461311833244/gothic_2_startet_nicht_windows_7.pdf
- https://cdn-cms.f-static.net/uploads/4383704/normal_5f965cab93247.pdf
- https://cdn-cms.f-static.net/uploads/4366405/normal_5f87108f220be.pdf
- https://cdn-cms.f-static.net/uploads/4374542/normal_5f89358d2ced6.pdf
- https://cdn-cms.f-static.net/uploads/4384851/normal_5f8f584549b16.pdf
- https://cdn-cms.f-static.net/uploads/4373297/normal_5f8bd03528de3.pdf
- https://cdn-cms.f-static.net/uploads/4382619/normal_5f8bb5118c5a6.pdf
- https://cdn-cms.f-static.net/uploads/4366358/normal_5f8751ca358cf.pdf
- https://cdn-cms.f-static.net/uploads/4419644/normal_5f95f985243e9.pdf
- https://cdn-cms.f-static.net/uploads/4408330/normal_5f9580fab92f0.pdf
- https://cdn-cms.f-static.net/uploads/4409604/normal_5f96f0228ca6d.pdf
- https://wivixilor.weebly.com/uploads/1/3/4/3/134371520/9293011.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/514ff4a4d.pdf
- https://uploads.strikinglycdn.com/files/a7699c34-0446-4a6c-8e8e-232ec391dfbc/31763768712.pdf
- https://uploads.strikinglycdn.com/files/5f46eac6-f866-493e-ac6c-f5b6671ad5b6/gofaxumamokuvosekagejom.pdf
- https://uploads.strikinglycdn.com/files/847b5dd2-a276-4aab-a11d-4ca688960f8f/99434010911.pdf
- https://uploads.strikinglycdn.com/files/6482d942-b280-4c87-a76e-89e8ee46c096/89849956672.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- wivixilor.weebly.com
- tivakoxidedopa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report