SUSPICIOUS — normal_5fa77f68e0f7c.pdf
SUSPICIOUS — normal_5fa77f68e0f7c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e8fc2888416d79a772f459b7143dd269d6369c66be89dbff8a60096ab8743028 - SHA-1:
d2ab1657a2eb7b60dbbe99d07a3bdf5b1b7e3449 - MD5:
71dbf669c001e17d14632920ed7f81f0 - ssdeep:
768:ngGzpDLDwGcIyQlFeVn9IYKt5ekEhZqH48b6gSn6qBlGy6+tbP6FNVQL:gGFfsGW9IZek2o48bE66Gy9byFNVQL - TLSH:
T131319EF39157CE8C6A87AB27AEB61094658DC78C6032D2A414D93B6CC9BC1FC7E41871 - Submitted as: normal_5fa77f68e0f7c.pdf
- File type: pdf · Size: 42167 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafffi.ru/123?keyword=grim+dawn+shrine+locations+forgotten+gods, https://cdn-cms.f-static.net/uploads/4387244/normal_5f9000d7ad35e.pdf, https://cdn-cms.f-static.net/uploads/4387811/normal_5f993563758a2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://trafffi.ru/123?keyword=grim+dawn+shrine+locations+forgotten+gods
- https://cdn-cms.f-static.net/uploads/4387244/normal_5f9000d7ad35e.pdf
- https://s3.amazonaws.com/vuforewebub/zimuteza.pdf
- https://s3.amazonaws.com/fejenijovekozu/navy_start_guide_2019.pdf
- https://cdn-cms.f-static.net/uploads/4387811/normal_5f993563758a2.pdf
- https://cdn-cms.f-static.net/uploads/4404105/normal_5f93cc8a05590.pdf
- https://cdn-cms.f-static.net/uploads/4366319/normal_5f89e90ce106c.pdf
- https://s3.amazonaws.com/liguwubore/marc_pro_plus_charger.pdf
- https://s3.amazonaws.com/novipaliwid/hancock_whitney_bank_login_page.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f8700a4495b8.pdf
- https://s3.amazonaws.com/timafatafej/warmane_sub_rogue_pvp_guide.pdf
- https://s3.amazonaws.com/xumakomowi/wonderbook_jeff_vandermeer.pdf
- https://s3.amazonaws.com/fadobirak/40877716257.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffi.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report