SUSPICIOUS — normal_5f874922d31d6.pdf
SUSPICIOUS — normal_5f874922d31d6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ea27349d3a909960530e5b23564af475fb4ac5d722cc472d3e4373504a8456a8 - SHA-1:
cd3de308c12527e382bec0bd84bffc80456cdbb8 - MD5:
2d070cf5ccea90ccb1593ee27e73ee0c - ssdeep:
1536:cqGFHpmAR+RPu2BIU3ZYciIa7V3FP88WuPwZqC:cTFHpstumI7lzVVP8/t - TLSH:
T13D34AFF311A7DD8C7ACA97076CEA1261108ACB8D2232D7A095CC772DD4BC2BD9E50C61 - Submitted as: normal_5f874922d31d6.pdf
- File type: pdf · Size: 56106 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=brahma+purana+in+bengali+pdf, https://uploads.strikinglycdn.com/files/f590235c-4f8c-4bd6-8dae-324a9aeaa75b/fakebo.pdf, https://uploads.strikinglycdn.com/files/8dd8390e-d12f-4936-a777-c6de4cfb67ba/pebunaxupopenobelabeperol.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=brahma+purana+in+bengali+pdf
- https://uploads.strikinglycdn.com/files/f590235c-4f8c-4bd6-8dae-324a9aeaa75b/fakebo.pdf
- https://uploads.strikinglycdn.com/files/8dd8390e-d12f-4936-a777-c6de4cfb67ba/pebunaxupopenobelabeperol.pdf
- https://uploads.strikinglycdn.com/files/c4f96072-25cb-404e-a0ed-e08472c4a4d7/14445674227.pdf
- https://uploads.strikinglycdn.com/files/14932439-b33c-481b-9223-e74c5e4ff661/9537170270.pdf
- https://site-1041682.mozfiles.com/files/1041682/11474230069.pdf
- https://site-1038733.mozfiles.com/files/1038733/78146617085.pdf
- https://site-1042720.mozfiles.com/files/1042720/kubixekozutoxu.pdf
- https://site-1040595.mozfiles.com/files/1040595/15191119331.pdf
- https://site-1038799.mozfiles.com/files/1038799/73094850258.pdf
- https://site-1036873.mozfiles.com/files/1036873/dalivuvarej.pdf
- https://site-1038517.mozfiles.com/files/1038517/88768747638.pdf
- https://site-1043291.mozfiles.com/files/1043291/6736492857.pdf
- https://site-1039217.mozfiles.com/files/1039217/bedadakitaguwezamuvibegu.pdf
- https://site-1040250.mozfiles.com/files/1040250/petemepinirotolozad.pdf
- https://site-1039346.mozfiles.com/files/1039346/21849230493.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f873e947e03b.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f871c04c3c09.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f87271aceb67.pdf
- https://cdn-cms.f-static.net/uploads/4367302/normal_5f873e5fd17f0.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f86fa4b7d669.pdf
- https://site-1041301.mozfiles.com/files/1041301/xapebejidogebajavojuse.pdf
- https://site-1048552.mozfiles.com/files/1048552/96205210089.pdf
- https://site-1036698.mozfiles.com/files/1036698/86459985843.pdf
- https://site-1042199.mozfiles.com/files/1042199/xulosulikosenasu.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1041682.mozfiles.com
- site-1038733.mozfiles.com
- site-1042720.mozfiles.com
- site-1040595.mozfiles.com
- site-1038799.mozfiles.com
- site-1036873.mozfiles.com
- site-1038517.mozfiles.com
- site-1043291.mozfiles.com
- site-1039217.mozfiles.com
- site-1040250.mozfiles.com
- site-1039346.mozfiles.com
- cdn-cms.f-static.net
- site-1041301.mozfiles.com
- site-1048552.mozfiles.com
- site-1036698.mozfiles.com
- site-1042199.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report