SUSPICIOUS — normal_5f89575679a57.pdf
SUSPICIOUS — normal_5f89575679a57.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ff910baf5f70cf1016a2161122cc4d74a66277c0ca9fbb916b3eebeabf0a0ed5 - SHA-1:
ddcd2826c06af448989f47c9a7d769db154ee0d8 - MD5:
eeb2cfb815c1dbc98cec85545df40c91 - ssdeep:
768:dgGzpDMp7CM84suNMKCIAFSfhJEmTVjM6YzJw8LarNxLJU8+a5QIZuRFelAkW:eGFIp2Sp+mTVxYFwEiRJU8j5QIaFelAJ - TLSH:
T1C3328DF34067EE8C778B6B17AEEA1568604AC28D2132A790148C776DD47C9FD3F40A61 - Submitted as: normal_5f89575679a57.pdf
- File type: pdf · Size: 43939 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=loch+ness+map+pdf, https://cdn.shopify.com/s/files/1/0498/4002/9851/files/output_devices_list.pdf, https://cdn.shopify.com/s/files/1/0434/2788/9319/files/constructing_triangles_worksheet_grade_7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=loch+ness+map+pdf
- https://cdn.shopify.com/s/files/1/0498/4002/9851/files/output_devices_list.pdf
- https://cdn.shopify.com/s/files/1/0434/2788/9319/files/constructing_triangles_worksheet_grade_7.pdf
- https://cdn.shopify.com/s/files/1/0462/8463/6320/files/lupuvikuzilamunuzewonox.pdf
- https://cdn.shopify.com/s/files/1/0500/6698/1059/files/tekurexarolovago.pdf
- https://uploads.strikinglycdn.com/files/86167a71-948f-4a85-b3df-7c5651b0193d/fomujot.pdf
- https://cdn.shopify.com/s/files/1/0448/5578/7681/files/torque_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0478/2329/0527/files/aapka_muskurana_gazab_dha_gaya_video_mein.pdf
- https://uploads.strikinglycdn.com/files/195c6829-92d9-4642-9072-75b991a27af4/5105686498.pdf
- https://uploads.strikinglycdn.com/files/0b2077c8-b0b6-4dfd-847c-ce03746afafb/woruvumud.pdf
- https://uploads.strikinglycdn.com/files/5ee51709-5f2e-4f5b-96a3-5e51c128808b/99890650838.pdf
- https://uploads.strikinglycdn.com/files/68faf43b-d8ec-4665-84c6-c5d0918608d9/linebepatokoviralabimiwel.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f88f39ce5226.pdf
- https://cdn-cms.f-static.net/uploads/4368221/normal_5f8819c26f896.pdf
- https://cdn-cms.f-static.net/uploads/4368501/normal_5f882bd4e6ec6.pdf
- https://cdn-cms.f-static.net/uploads/4367952/normal_5f87ffb3912cc.pdf
- https://cdn-cms.f-static.net/uploads/4367017/normal_5f888adaa7263.pdf
- https://uploads.strikinglycdn.com/files/c2494a80-24ee-4dc4-815f-c899925ffc7a/nujajidadezamobetutom.pdf
- https://uploads.strikinglycdn.com/files/f7474419-2749-40d2-a9db-858f2079e6b1/bexagezemam.pdf
- https://uploads.strikinglycdn.com/files/e896dd5d-5e0d-43af-a069-8cd5f09b616f/novarepumatimifosox.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report