SUSPICIOUS — normal_5f8881669b771.pdf
SUSPICIOUS — normal_5f8881669b771.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
eb049ba8da9c4a2a01c7fe8b41254a9f801fbaa09bbc4236042fec17fdfb5e2d - SHA-1:
bb8b7dbae01e3edd39595f3e46a32c1b30e6f8ab - MD5:
be0c3ba8bc1fa7fdec9b4eb6ad8c77d1 - ssdeep:
768:AgGzpDQeBUwspgElrlpzAUaE/J1xmlkKJYC5Iyg2NZTIVdoM+RTpC:NGFkeyws1lxBmdJDN3NxIDx+9pC - TLSH:
T104338DF340ABDD0CBACAA703B9F61468918DD648A173DB9409946B2DD0BC3BD7F10A51 - Submitted as: normal_5f8881669b771.pdf
- File type: pdf · Size: 49648 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=adjusting+trial+balance+worksheet, https://uploads.strikinglycdn.com/files/f6f082c2-f120-42e6-9ac3-6be2719df52f/67798607399.pdf, https://uploads.strikinglycdn.com/files/f6f9ff6b-11a0-423c-add1-00c11163cb47/49990855375.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=adjusting+trial+balance+worksheet
- https://uploads.strikinglycdn.com/files/f6f082c2-f120-42e6-9ac3-6be2719df52f/67798607399.pdf
- https://uploads.strikinglycdn.com/files/f6f9ff6b-11a0-423c-add1-00c11163cb47/49990855375.pdf
- https://uploads.strikinglycdn.com/files/7eac25c1-c8c6-4535-ab4f-dd08a87bb9be/vufijidazonupiwematerunur.pdf
- https://site-1041289.mozfiles.com/files/1041289/rekanawumodobegotajetefu.pdf
- https://site-1041295.mozfiles.com/files/1041295/tazujuruwexifowiz.pdf
- https://site-1038614.mozfiles.com/files/1038614/tufapitibikawafagogo.pdf
- https://site-1040563.mozfiles.com/files/1040563/32922144523.pdf
- https://site-1044107.mozfiles.com/files/1044107/bagitiranu.pdf
- https://uploads.strikinglycdn.com/files/d0927bc1-b285-4df5-a5c3-1c76292fafc8/kilesenorewimil.pdf
- https://uploads.strikinglycdn.com/files/8a131a0f-6f68-4bdc-83a9-50ba511c7a98/70558547881.pdf
- https://cdn.shopify.com/s/files/1/0483/5613/0965/files/descargar_minecraft_apk_full_espaol_gratis.pdf
- https://cdn.shopify.com/s/files/1/0479/1359/9143/files/netgear_wgr614_v9_manual.pdf
- https://cdn.shopify.com/s/files/1/0496/0606/6325/files/antecedentes_penales_venezuela_por_internet.pdf
- https://cdn.shopify.com/s/files/1/0483/4594/0128/files/adventure_quest_warrior_guide.pdf
- https://site-1042286.mozfiles.com/files/1042286/histologia_veterinaria_libro.pdf
- https://site-1042887.mozfiles.com/files/1042887/zaguxojaratejogav.pdf
- https://site-1042767.mozfiles.com/files/1042767/vizofepekadikekal.pdf
- https://site-1039919.mozfiles.com/files/1039919/23578991662.pdf
- https://site-1037228.mozfiles.com/files/1037228/34312827716.pdf
- https://site-1042286.mozfiles.com/files/1042286/gitoxenewazugemekisi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1041289.mozfiles.com
- site-1041295.mozfiles.com
- site-1038614.mozfiles.com
- site-1040563.mozfiles.com
- site-1044107.mozfiles.com
- cdn.shopify.com
- site-1042286.mozfiles.com
- site-1042887.mozfiles.com
- site-1042767.mozfiles.com
- site-1039919.mozfiles.com
- site-1037228.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report