SUSPICIOUS — normal_5f875654cdea8.pdf
SUSPICIOUS — normal_5f875654cdea8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e22f192c8fcf4199b4c19c813cebe1b4e134b7e3f15b7db5776891bcf21d417b - SHA-1:
4668cec5bd7a1537de5da10a642f22620f9b6691 - MD5:
29b2c4afe665f7f9f853eafc580d1a80 - ssdeep:
1536:uGFDeInHVo6uxHEZJjSLalJAGmXHlP/LIXGmulPDyA5:XFDeIn1o6SHEZLlJzYPTIr8l - TLSH:
T1E636BFF3549BED4C2B8B6B53E9AB01652089DA8DA133DBD4488CB72CC1BC1BD7E11911 - Submitted as: normal_5f875654cdea8.pdf
- File type: pdf · Size: 68043 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=eosinophilic+esophagitis+guidelines+pediatric, https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/buforedikefenas.pdf, https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=eosinophilic+esophagitis+guidelines+pediatric
- https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/buforedikefenas.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/1346883.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/zipudefoxejo_sowuval_kixenonewukas_jepetoboselabu.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/7240363.pdf
- https://uploads.strikinglycdn.com/files/92952b6a-2159-4aa8-a117-0e0bef1e8e3f/mipuzijararanobax.pdf
- https://uploads.strikinglycdn.com/files/55d9abd4-977d-475e-abb7-6928d868e93f/rewif.pdf
- https://uploads.strikinglycdn.com/files/bea35f5e-5837-4130-832e-9e211429957c/93287530798.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f8737e55ba4c.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f873a036a72e.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f87022a2fc72.pdf
- https://cdn-cms.f-static.net/uploads/4366653/normal_5f874a489535c.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f871c452289f.pdf
- https://cdn.shopify.com/s/files/1/0431/0790/9794/files/lubegis.pdf
- https://cdn.shopify.com/s/files/1/0437/5969/8077/files/washington_state_sctatch_tickets_time_slot.pdf
- https://cdn-cms.f-static.net/uploads/4366024/normal_5f87405a93e17.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f8744af61a27.pdf
- https://cdn.shopify.com/s/files/1/0477/6201/4364/files/farewell_to_manzanar_test_answers.pdf
- https://cdn.shopify.com/s/files/1/0493/4202/1791/files/papa_johns_supreme_pizza.pdf
- https://cdn.shopify.com/s/files/1/0498/1594/5371/files/jason_cermak_family.pdf
- https://cdn.shopify.com/s/files/1/0266/8888/0826/files/wow_classic_pvp_guide_hunter.pdf
- https://cdn.shopify.com/s/files/1/0436/6991/3753/files/super_castlevania_4_rom.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- gemaxudemaxepeb.weebly.com
- dimaxafazeza.weebly.com
- boguvetasitob.weebly.com
- nogafuku.weebly.com
- nudojafobedem.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report