SUSPICIOUS — normal_5f8750bd00a07.pdf
SUSPICIOUS — normal_5f8750bd00a07.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d85b77ad9afe3b5527f9d4fffdc0e6ceee4aea10b97870e981ab3b748761b3f4 - SHA-1:
65ace03ddc22f78eba5346a8a4d04fe93ce62785 - MD5:
6b68da46f38d0ac3affe0993b9826b50 - ssdeep:
768:YgGzpDnpVR4RjlE+1bRYAeX5xEwFKcqjiv9kF78ZTfArWI:1GF7pHAeX5pKcqWv2F47ArWI - TLSH:
T15F318DF360A7DD4C768BAB53AEBA10586589C38C5132A3A455D8777CC8BC6BC7E10821 - Submitted as: normal_5f8750bd00a07.pdf
- File type: pdf · Size: 40739 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=convert+jpg+to+pdf+free+software+download, https://uploads.strikinglycdn.com/files/205444d0-7639-4d32-95d3-58c2ab8b4791/diloz.pdf, https://uploads.strikinglycdn.com/files/8608d5c5-f722-4c40-a7e3-e749ddec9849/tokuligezetuxe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=convert+jpg+to+pdf+free+software+download
- https://uploads.strikinglycdn.com/files/205444d0-7639-4d32-95d3-58c2ab8b4791/diloz.pdf
- https://uploads.strikinglycdn.com/files/8608d5c5-f722-4c40-a7e3-e749ddec9849/tokuligezetuxe.pdf
- https://uploads.strikinglycdn.com/files/85d19327-c946-479e-aa4c-239a8da03c03/48202904505.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f872927b219b.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f87019a52540.pdf
- https://cdn.shopify.com/s/files/1/0483/2192/1177/files/frigidaire_gallery_gas_range_service_manual.pdf
- https://cdn.shopify.com/s/files/1/0500/3178/8182/files/8213548885.pdf
- https://cdn.shopify.com/s/files/1/0432/8839/5936/files/76992670183.pdf
- https://site-1042092.mozfiles.com/files/1042092/nilepexu.pdf
- https://site-1048208.mozfiles.com/files/1048208/17766596462.pdf
- https://site-1038830.mozfiles.com/files/1038830/meroxopexagap.pdf
- https://site-1038932.mozfiles.com/files/1038932/65120490590.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f87260bcf6a6.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f873131aedf3.pdf
- https://site-1038729.mozfiles.com/files/1038729/moguvipureboruwofakax.pdf
- https://site-1037261.mozfiles.com/files/1037261/definition_of_listening_menurut_para_ahli.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1042092.mozfiles.com
- site-1048208.mozfiles.com
- site-1038830.mozfiles.com
- site-1038932.mozfiles.com
- site-1038729.mozfiles.com
- site-1037261.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report