SUSPICIOUS — normal_5f91f204367f4.pdf
SUSPICIOUS — normal_5f91f204367f4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ff3f0938b514015bdd764c45296801882a2f3445a593d2fddb471b9e1befdf5e - SHA-1:
f642f29ff0ba898843e467f15eadfaf4dc5115fb - MD5:
44c0ad01d97b56babdca779d70c712d7 - ssdeep:
1536:AGF/pbkqfjDJfK4y7W2iacjiFwChk1j9hF4GUKt:NF/pbxjDFo7W2/JWChwjPF49g - TLSH:
T133359EF350A3ED8D7A8E6F03ADA7115A644AD6887133976004CC7B2CD47C6BDBE10A52 - Submitted as: normal_5f91f204367f4.pdf
- File type: pdf · Size: 61075 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=creativity+inc+full+pdf, https://cdn-cms.f-static.net/uploads/4385197/normal_5f901e1287938.pdf, https://cdn-cms.f-static.net/uploads/4366020/normal_5f8701837245a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=creativity+inc+full+pdf
- https://cdn-cms.f-static.net/uploads/4385197/normal_5f901e1287938.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f8701837245a.pdf
- https://cdn-cms.f-static.net/uploads/4379370/normal_5f91ee41de49e.pdf
- https://cdn-cms.f-static.net/uploads/4370078/normal_5f88cb40f3406.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f8774a2789f7.pdf
- https://cdn.shopify.com/s/files/1/0466/5281/7573/files/oxford_spanish_dictionary_full_4.3.069_apkdata.pdf
- https://cdn.shopify.com/s/files/1/0493/7108/7007/files/lowrance_elite_7_ti_manual_dansk.pdf
- https://cdn.shopify.com/s/files/1/0434/2464/5272/files/rukefopasaje.pdf
- https://cdn.shopify.com/s/files/1/0266/8196/6779/files/97172909284.pdf
- https://cdn.shopify.com/s/files/1/0503/8650/1806/files/ul_prospectus_2020_download.pdf
- https://uploads.strikinglycdn.com/files/64025d12-59ea-40d0-8297-3e0cbf803f3d/duzugotajexusupovavi.pdf
- https://uploads.strikinglycdn.com/files/8bc7e396-e7cb-4e7e-b4bf-8ba19ef7ccce/65840339868.pdf
- https://uploads.strikinglycdn.com/files/2ad4d16d-78bb-425d-95b8-c4ce88305510/32595048433.pdf
- https://uploads.strikinglycdn.com/files/a0553d64-f8f1-4e68-bbee-a1ec151dc67b/zudezevegerawozopowoza.pdf
- https://uploads.strikinglycdn.com/files/20920057-0e9c-4ec6-a0f4-9b76705f6c2f/yakuza_kiwami_cheats.pdf
- https://nitetezelimon.weebly.com/uploads/1/3/1/4/131438651/xifid_dakakezinetuti_fixabunu_tujoramodewusos.pdf
- https://porelananov.weebly.com/uploads/1/3/0/7/130775759/voreneb-pejulusi.pdf
- https://nunoperiv.weebly.com/uploads/1/3/1/8/131856708/pakare.pdf
- https://turomanusogagi.weebly.com/uploads/1/3/1/4/131453559/61f82309.pdf
- https://s3.amazonaws.com/tapexiw/mikanopusagokatazoxu.pdf
- https://s3.amazonaws.com/mijedusovineti/gabuxap.pdf
- https://s3.amazonaws.com/fogibi/directory_commands_in_linux.pdf
- https://s3.amazonaws.com/mijedusovineti/definition_worksheet.pdf
- https://s3.amazonaws.com/sugaguxagu/92547653130.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- nitetezelimon.weebly.com
- porelananov.weebly.com
- nunoperiv.weebly.com
- turomanusogagi.weebly.com
- s3.amazonaws.com
- gimejexoxixaza.weebly.com
- femitinekabel.weebly.com
- dutitujazekap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report