SUSPICIOUS — normal_5f871adc64e54.pdf
SUSPICIOUS — normal_5f871adc64e54.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
db830868942a5cebc3be6bd221b297a28098cf24611d024839a8c581ecf05ae0 - SHA-1:
3ba80bf1a2b061abd7550a80e10230c052068d0a - MD5:
be289d2f8825c63cd9f7b7070c1b3a62 - ssdeep:
768:zgGzpDFjp+gPbyRdfggq9FVBszjGJruKOYJzRtc6GQA1TzdDqZRDRdufygTZrZB0:MGFtphwzjbVGrdGeIfygTZ1BJtHtu7mK - TLSH:
T18C337CF310FBDD4C7ACB9B17ADAA256D944DE74850239BA4448C672CC8BC6BE7E00911 - Submitted as: normal_5f871adc64e54.pdf
- File type: pdf · Size: 49012 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=lines+of+symmetry+worksheets+for+grade+1, https://uploads.strikinglycdn.com/files/5c17c5c6-4250-4c5e-8a22-c8ad47994ba3/34699308207.pdf, https://uploads.strikinglycdn.com/files/c0aefde7-f338-4684-bfe4-c0d9579c6d5e/lajixuxake.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=lines+of+symmetry+worksheets+for+grade+1
- https://uploads.strikinglycdn.com/files/5c17c5c6-4250-4c5e-8a22-c8ad47994ba3/34699308207.pdf
- https://uploads.strikinglycdn.com/files/c0aefde7-f338-4684-bfe4-c0d9579c6d5e/lajixuxake.pdf
- https://uploads.strikinglycdn.com/files/62e1bee1-3785-4b9f-add3-ea132fe8fcdd/gixiwamijupemugitorawavaj.pdf
- https://uploads.strikinglycdn.com/files/ee854bc1-1125-42a1-b7d1-fde01761bec5/66381502814.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f871a75a3cdd.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f86f941d03f7.pdf
- https://cdn-cms.f-static.net/uploads/4365542/normal_5f87067ed3b21.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f871147ae901.pdf
- https://cdn-cms.f-static.net/uploads/4366005/normal_5f8708f7b0c12.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f870b3f626e6.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f86f71607251.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f87158249d57.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f86fa70cac32.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f870c8541ba2.pdf
- https://uploads.strikinglycdn.com/files/ba05e8a3-0ba5-497e-9237-c096935d567c/84805823721.pdf
- https://uploads.strikinglycdn.com/files/20657be9-8f9e-49c3-8992-90ab4f41b971/44237831165.pdf
- https://uploads.strikinglycdn.com/files/59bf830a-4e85-455f-99f3-cb137edd76ee/71260588076.pdf
- https://uploads.strikinglycdn.com/files/ca19c8e3-ac5e-4354-90c0-740e339fb1d0/lozerodulozivetedaw.pdf
- https://uploads.strikinglycdn.com/files/461e0e1a-a98b-4ff2-8e3f-41bbb0aa9ded/9490422308.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/7922058.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/xefafimofaxeparekuji.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/jasamejug-jenutuzudemeluf.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/7904132.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- genigudepa.weebly.com
- fijojonibiw.weebly.com
- mojivimimujovo.weebly.com
- jakedekokobara.weebly.com
- keniwuki.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report