SUSPICIOUS — normal_5f87e682976ea.pdf
SUSPICIOUS — normal_5f87e682976ea.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e8fe786080e46d4321c425857784388304af93c418af8298189c685cf5e4deac - SHA-1:
fe27e74d7ff26af84cb5dbb9ae989c278984b6c7 - MD5:
b8659fee65c44b8393e53f60166761ea - ssdeep:
1536:lGFYpGJjCojVlRf5THH4I7RsHfjr43o3w:4FYp4FRf5THH4I7uHof - TLSH:
T12F339EF350ABDD4C7987AB036EBA189D964AD3886133A7B05488376DC07C77D6F40864 - Submitted as: normal_5f87e682976ea.pdf
- File type: pdf · Size: 51176 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=fifa+18+4411+player+instructions, https://site-1039749.mozfiles.com/files/1039749/63058815886.pdf, https://site-1038555.mozfiles.com/files/1038555/25566814235.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=fifa+18+4411+player+instructions
- https://site-1039749.mozfiles.com/files/1039749/63058815886.pdf
- https://site-1038555.mozfiles.com/files/1038555/25566814235.pdf
- https://site-1043095.mozfiles.com/files/1043095/68133128146.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87102768cc7.pdf
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f86fa9694487.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f8764a864996.pdf
- https://cdn-cms.f-static.net/uploads/4366344/normal_5f870e389d026.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f87059cbff7a.pdf
- https://uploads.strikinglycdn.com/files/c85ee16d-fa44-43bc-b816-8859f7424625/44812415975.pdf
- https://uploads.strikinglycdn.com/files/5eeacb02-0e4a-4f18-bb6b-5a5877b80f8c/jezofajujajojo.pdf
- https://uploads.strikinglycdn.com/files/749a4cab-26ea-48dc-a78f-c040d9d3bf9e/takidagivalurumogebatap.pdf
- https://uploads.strikinglycdn.com/files/7c90fd33-8a0a-4ad4-891c-7d48c707578c/texakunizufixuropoxurosa.pdf
- https://uploads.strikinglycdn.com/files/4273dcbc-84af-49f3-9cb1-b17ec94489f3/wafatobimifanig.pdf
- https://uploads.strikinglycdn.com/files/efb1db51-8c43-4a1c-9a11-8f6539d14409/guzaleneriwavelevaned.pdf
- https://uploads.strikinglycdn.com/files/8bc7f29a-0955-4073-b617-a5115b76f5c8/14254720917.pdf
- https://uploads.strikinglycdn.com/files/b0d82894-2fdd-4c47-96bf-d1fa37b27364/nuzokaxovisuvenezape.pdf
- https://uploads.strikinglycdn.com/files/d797b990-2111-4d7c-8c26-49fc6f332225/97196120509.pdf
- https://uploads.strikinglycdn.com/files/685e7642-8c82-4041-b4b3-bc3da273ddb3/zanosekimo.pdf
- https://site-1041282.mozfiles.com/files/1041282/95607538624.pdf
- https://site-1039688.mozfiles.com/files/1039688/zuwugebazimaremoki.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- site-1039749.mozfiles.com
- site-1038555.mozfiles.com
- site-1043095.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1041282.mozfiles.com
- site-1039688.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report