SUSPICIOUS — normal_5f872f66a50aa.pdf
SUSPICIOUS — normal_5f872f66a50aa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
dfb808742f188d681b80f3f33d3d3df8095fb140bee80cfeebd50fc752ad18d0 - SHA-1:
5f5fa8d32e4af46510e5a3cc54132c940f210c2b - MD5:
9924096b99d98095ad3bce45458556c8 - ssdeep:
768:wgGzpDZJpGvaGll0cJo9nXR++Lw9qrZ0Z7UPIhEjACmVTWT9+qJ55Guk:dGFrpaTWpXfrZ0ZwPIGjACmATAqJ55Xk - TLSH:
T17C328EF310A7DC8C7BC7AB07ADE701A5618AD7496237976048CC2B2DC4AC6AE6E11461 - Submitted as: normal_5f872f66a50aa.pdf
- File type: pdf · Size: 44800 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=barn+owl+food+web+worksheet, https://uploads.strikinglycdn.com/files/a90d2e45-866f-4100-a2c2-5956c81a1157/69409522791.pdf, https://uploads.strikinglycdn.com/files/9c55c72a-645c-46f6-a665-3c210dd73920/mumar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=barn+owl+food+web+worksheet
- https://uploads.strikinglycdn.com/files/a90d2e45-866f-4100-a2c2-5956c81a1157/69409522791.pdf
- https://uploads.strikinglycdn.com/files/9c55c72a-645c-46f6-a665-3c210dd73920/mumar.pdf
- https://uploads.strikinglycdn.com/files/1f309dff-5fa8-43a1-b28e-5d26a7612e93/13051407179.pdf
- https://uploads.strikinglycdn.com/files/b6465404-1bbd-49ae-84f5-b895ba1475e6/xasedirokamelijame.pdf
- https://site-1043794.mozfiles.com/files/1043794/88185842832.pdf
- https://site-1043855.mozfiles.com/files/1043855/koviwigivi.pdf
- https://site-1038345.mozfiles.com/files/1038345/gupalugef.pdf
- https://site-1043698.mozfiles.com/files/1043698/lobabegutanep.pdf
- https://site-1039604.mozfiles.com/files/1039604/vadujewodogalajujulo.pdf
- https://uploads.strikinglycdn.com/files/22ade46f-94c3-4dfd-9e29-0263f6aaabb3/55889178639.pdf
- https://uploads.strikinglycdn.com/files/5d888ec5-3cd8-47bc-b948-c528c4879d5d/wasurazu.pdf
- https://uploads.strikinglycdn.com/files/1077eb79-8607-4604-8cae-af9b23d23a8e/3620110698.pdf
- https://uploads.strikinglycdn.com/files/32ba1aea-dffd-4bc0-a905-089bbf9ab843/47254728467.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kadupe_ripovu_jozovagazemewe.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/5058122.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/9298899.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/gelitu.pdf
- https://cdn-cms.f-static.net/uploads/4366371/normal_5f87118c1233d.pdf
- https://cdn-cms.f-static.net/uploads/4366027/normal_5f871a445316c.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f872dbb3a0fb.pdf
- https://uploads.strikinglycdn.com/files/2b002373-fbd8-4417-a2ba-572f3b68652d/51484461108.pdf
- https://uploads.strikinglycdn.com/files/5f27631b-dfdf-413b-9311-b1d200aa747f/17547134718.pdf
- https://uploads.strikinglycdn.com/files/94f2be6e-af91-4380-81e2-c52b671e85f1/tokuwabazozufisamedifasof.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1043794.mozfiles.com
- site-1043855.mozfiles.com
- site-1038345.mozfiles.com
- site-1043698.mozfiles.com
- site-1039604.mozfiles.com
- gimejexoxixaza.weebly.com
- povutepumik.weebly.com
- boguvetasitob.weebly.com
- tejigenunonim.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report