SUSPICIOUS — normal_5f8724956f270.pdf
SUSPICIOUS — normal_5f8724956f270.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
dbd62d2490dbfe7f2f44538203e8ed323ef4ed56f367fbed019014d128a9399c - SHA-1:
b2d2e935708d2755c458cd030292e9be2c66bd51 - MD5:
753030edaf90e8df3946a6d17bfbfb10 - ssdeep:
768:igGzpDipodpZ12KLq4H3LMwJujIaP6pOYOfeBUAUwCgNkw:/GFepuaU2MUAbCgNkw - TLSH:
T16D308DF30097EC4DBAC79B03ACEB15692089C78D623397A05488776DD4BC6BE7E50960 - Submitted as: normal_5f8724956f270.pdf
- File type: pdf · Size: 37931 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=self+charging+electric+bike+pdf, https://site-1044200.mozfiles.com/files/1044200/suzaduburali.pdf, https://site-1039809.mozfiles.com/files/1039809/norenusodolutegowaginakuv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=self+charging+electric+bike+pdf
- https://site-1044200.mozfiles.com/files/1044200/suzaduburali.pdf
- https://site-1039809.mozfiles.com/files/1039809/norenusodolutegowaginakuv.pdf
- https://site-1041598.mozfiles.com/files/1041598/92885260540.pdf
- https://site-1038397.mozfiles.com/files/1038397/nepunoda.pdf
- https://site-1048194.mozfiles.com/files/1048194/6184168675.pdf
- https://uploads.strikinglycdn.com/files/2c119dc0-9c28-4f6c-b687-f11b6b9ccdd4/bisimafe.pdf
- https://uploads.strikinglycdn.com/files/65efb4f2-7d97-4625-b3de-daade8f01e2a/bofifebebini.pdf
- https://uploads.strikinglycdn.com/files/448259f9-d4f6-4489-b458-89b03af5a7fd/43221822544.pdf
- https://uploads.strikinglycdn.com/files/e76eff60-0823-453b-8ff2-00817a82a90e/47331587502.pdf
- https://uploads.strikinglycdn.com/files/2a66a949-7265-4dc2-8686-3fa4e48627e0/44149411455.pdf
- https://cdn.shopify.com/s/files/1/0431/0876/1751/files/komewe.pdf
- https://cdn.shopify.com/s/files/1/0427/6381/3020/files/download_hotstar_pro_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0501/2668/4320/files/kingdom_rush_strategy.pdf
- https://cdn.shopify.com/s/files/1/0266/7829/6746/files/food_near_me_healthy.pdf
- https://cdn.shopify.com/s/files/1/0266/8491/5906/files/zepopoju.pdf
- https://cdn.shopify.com/s/files/1/0482/2653/3528/files/habbo_swat_ranks.pdf
- https://cdn.shopify.com/s/files/1/0495/9895/5684/files/rudolph_shiny_new_year.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f86f42213348.pdf
- https://cdn-cms.f-static.net/uploads/4365551/normal_5f871ec86960e.pdf
- https://cdn-cms.f-static.net/uploads/4366350/normal_5f871ee44eb9f.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f8708652c8f8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- site-1044200.mozfiles.com
- site-1039809.mozfiles.com
- site-1041598.mozfiles.com
- site-1038397.mozfiles.com
- site-1048194.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report