SUSPICIOUS — normal_5f95b8573eca6.pdf
SUSPICIOUS — normal_5f95b8573eca6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
eeefa8ac593247fa1b0a892e843e9168ff1b5b97d74642e9777565f815d9539e - SHA-1:
3e58c8206ad1c6fb88ddb893538deceeb6068b14 - MD5:
e42bc69202d6900df22917248f9bc1c5 - ssdeep:
768:fgGzpDmpy2kP/+a2naxFbok4dkAuBMKb+0saThA2UH7X15KRrADcha4I8hi3H1:oGFKpM+GFb1eb97X14ecQl3H1 - TLSH:
T174328EF350B7EC4C7A8B9F03AEE71559618AD78D61369B504488772DD0BCAEE3E10920 - Submitted as: normal_5f95b8573eca6.pdf
- File type: pdf · Size: 46087 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=tour+guide+certification+los+angeles, https://uploads.strikinglycdn.com/files/085150d5-5040-45a9-b0b6-13b850740ee6/42970264321.pdf, https://uploads.strikinglycdn.com/files/22332d7f-e49f-400f-8c23-b943b4bab8f2/97831856909.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=tour+guide+certification+los+angeles
- https://uploads.strikinglycdn.com/files/085150d5-5040-45a9-b0b6-13b850740ee6/42970264321.pdf
- https://uploads.strikinglycdn.com/files/22332d7f-e49f-400f-8c23-b943b4bab8f2/97831856909.pdf
- https://uploads.strikinglycdn.com/files/dd17e9be-c067-4b87-a451-20119a47ece0/52772780077.pdf
- https://uploads.strikinglycdn.com/files/092baa36-a732-4624-97e3-38bfeecd161d/xibodoborov.pdf
- https://cdn.shopify.com/s/files/1/0439/4732/7646/files/android_21_bnb_combos.pdf
- https://cdn.shopify.com/s/files/1/0430/2598/9785/files/12016465135.pdf
- https://cdn.shopify.com/s/files/1/0485/3671/5419/files/can_you_microwave_coated_paper_plates.pdf
- https://cdn.shopify.com/s/files/1/0268/7241/4380/files/51172213476.pdf
- https://mazofowi.weebly.com/uploads/1/3/4/3/134312703/7445071.pdf
- https://bogadisosupotaj.weebly.com/uploads/1/3/0/7/130776541/9956511.pdf
- https://vupimolafi.weebly.com/uploads/1/3/1/3/131398504/1084261.pdf
- https://vepezifu.weebly.com/uploads/1/3/4/2/134265798/95003434e69f6.pdf
- https://pufibifisap.weebly.com/uploads/1/3/4/4/134450659/3148104.pdf
- https://s3.amazonaws.com/tetazino/13474913222.pdf
- https://s3.amazonaws.com/vekodupiwarobi/rokapipazowabovubipem.pdf
- https://s3.amazonaws.com/bupaxomu/understanding_the_stock_market_for_beginners.pdf
- https://s3.amazonaws.com/xipavir/que_es_el_outsourcing.pdf
- https://s3.amazonaws.com/pazifetanegapu/lodakazuvubexanixajumovi.pdf
- https://gekeforoka.weebly.com/uploads/1/3/1/4/131438206/4510944.pdf
- https://xajapeni.weebly.com/uploads/1/3/4/3/134341300/kugodavuvi-vadevak-memanewadij-nosuvu.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f8a538a10c24.pdf
- https://cdn-cms.f-static.net/uploads/4380411/normal_5f8c85278456f.pdf
- https://cdn-cms.f-static.net/uploads/4368998/normal_5f8b84b7343e5.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- mazofowi.weebly.com
- bogadisosupotaj.weebly.com
- vupimolafi.weebly.com
- vepezifu.weebly.com
- pufibifisap.weebly.com
- s3.amazonaws.com
- gekeforoka.weebly.com
- xajapeni.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report