SUSPICIOUS — normal_5f88d8807b8b6.pdf
SUSPICIOUS — normal_5f88d8807b8b6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d43a74a799365c9e55567b9f91648e58d4451827db849a42e1354c8e9d105c02 - SHA-1:
786892d07347db2d48e3ece57bf6fdf62f2f5a44 - MD5:
e695bc03400830154cddc2fb2b58725f - ssdeep:
768:YgGzpD/p70Qim8LHoKDIQciCqI4HL+Z9slddLRqfgeKl8o3brcEc:1GFrp7DPivPLg9sBRqfBRobrbc - TLSH:
T12E328CF314A3ED8C7A869B17ADA311A5684DC34C6137E790448C7B2DC8FC6BD6E10961 - Submitted as: normal_5f88d8807b8b6.pdf
- File type: pdf · Size: 44236 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=esports+logo+maker+mod+apk, https://uploads.strikinglycdn.com/files/bbdcd16d-335b-4a5e-9772-3582d09d2100/67268742090.pdf, https://uploads.strikinglycdn.com/files/2f1051f8-a62f-4918-804e-7721a61907da/gupelesid.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=esports+logo+maker+mod+apk
- https://uploads.strikinglycdn.com/files/bbdcd16d-335b-4a5e-9772-3582d09d2100/67268742090.pdf
- https://uploads.strikinglycdn.com/files/2f1051f8-a62f-4918-804e-7721a61907da/gupelesid.pdf
- https://uploads.strikinglycdn.com/files/20124aad-f3f0-47ad-898d-ba3f57b9f1a7/39202792597.pdf
- https://uploads.strikinglycdn.com/files/c90514d6-93ca-48f9-9dd1-b2ae797d4783/dadijatikakibifazetudiwe.pdf
- https://uploads.strikinglycdn.com/files/cfb5a1f3-b611-4185-9378-06064d177d69/40351803072.pdf
- https://cdn-cms.f-static.net/uploads/4368758/normal_5f88c2151a3fb.pdf
- https://cdn-cms.f-static.net/uploads/4366655/normal_5f875f0385d45.pdf
- https://cdn-cms.f-static.net/uploads/4368503/normal_5f87dae92aa12.pdf
- https://cdn-cms.f-static.net/uploads/4372104/normal_5f88cdc1b1a6b.pdf
- https://cdn-cms.f-static.net/uploads/4367960/normal_5f8787ffbeafd.pdf
- https://cdn-cms.f-static.net/uploads/4368229/normal_5f88d281deb7a.pdf
- https://cdn-cms.f-static.net/uploads/4370541/normal_5f88b736079ff.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/wovexofek.pdf
- https://pezopipowom.weebly.com/uploads/1/3/1/4/131406060/zeleteruleful_wotavatak_zufomuvinuwa.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/059d55fbff3.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/2617268.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/5401885.pdf
- https://uploads.strikinglycdn.com/files/143a67ad-2784-46ee-8467-2de6e0bee546/metawavikixumujagejanefa.pdf
- https://uploads.strikinglycdn.com/files/3dd5f43d-cc1c-4fdc-abc8-c1dcd55c755a/takiles.pdf
- https://uploads.strikinglycdn.com/files/ff723d49-00a0-47a8-966e-8dee1f232f5a/jomafagatirogat.pdf
- https://uploads.strikinglycdn.com/files/5c0bdbb8-a58e-4227-8c59-f08e17c814f0/39054528029.pdf
- https://uploads.strikinglycdn.com/files/2567b5f6-eb37-428b-acdd-bbcc1f6e265c/zejoxujofibovepolugawep.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- jawasolasazilem.weebly.com
- pezopipowom.weebly.com
- mogilifus.weebly.com
- taxajadotediru.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report