SUSPICIOUS — normal_5f8d327e60c10.pdf
SUSPICIOUS — normal_5f8d327e60c10.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
060913056bafe4fbfec807a412c98dceeb79e50bbead302ed36872153cec6453 - SHA-1:
19ac8b645b7a992ae43d5bddc305b67aeeecf672 - MD5:
243c86fd837b9c939e18e0d3098bf25a - ssdeep:
768:nwgGzpDxp90zD20aLl/nsXCXwXPmM0zCssMyTTXVNIZAEBBZSTUa:ndGFtp7bwfmMz0yTTFSKERSTUa - TLSH:
T158329DF364C7ED4C7983AF1379E61468518AD38C2236976048CCB62CC4FC6AEBE51961 - Submitted as: normal_5f8d327e60c10.pdf
- File type: pdf · Size: 47513 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=writing+numbers+1-50+worksheet, https://uploads.strikinglycdn.com/files/8660e0e9-2c1c-402d-a1a1-7c5b265b3fd1/ronafisugus.pdf, https://uploads.strikinglycdn.com/files/581ec432-ba61-4c1e-a36d-cb9237cb3e4a/objective_first_for_spanish_speakers_self-study_pack_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=writing+numbers+1-50+worksheet
- https://uploads.strikinglycdn.com/files/8660e0e9-2c1c-402d-a1a1-7c5b265b3fd1/ronafisugus.pdf
- https://uploads.strikinglycdn.com/files/581ec432-ba61-4c1e-a36d-cb9237cb3e4a/objective_first_for_spanish_speakers_self-study_pack_download.pdf
- https://uploads.strikinglycdn.com/files/744a9158-bbe1-4526-b1de-223bd0e32b2d/dafolejoxo.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f88af5f91222.pdf
- https://cdn-cms.f-static.net/uploads/4369776/normal_5f87ecc8d52be.pdf
- https://uploads.strikinglycdn.com/files/66a46f3c-7058-44f5-8829-87a19027900a/tafigonenavelujidefod.pdf
- https://uploads.strikinglycdn.com/files/85b640c7-1ed6-49a8-8ec0-c3ec6372c584/nasawefulorenetiludubak.pdf
- https://uploads.strikinglycdn.com/files/fc661d15-1923-44ab-80b4-3b7f9ede5bf6/tilixepiduzuvagitox.pdf
- https://uploads.strikinglycdn.com/files/67a25701-2ee6-4ee8-bcc7-116453264707/palekunab.pdf
- https://uploads.strikinglycdn.com/files/3eafe3aa-5561-4e16-9d4d-a0435a110a0c/dafujometegupo.pdf
- https://cdn-cms.f-static.net/uploads/4368999/normal_5f8c8ab28779e.pdf
- https://cdn-cms.f-static.net/uploads/4367668/normal_5f89104d25221.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f8a933f567a5.pdf
- https://cdn-cms.f-static.net/uploads/4379491/normal_5f8c45c08f344.pdf
- https://uploads.strikinglycdn.com/files/d83aaa79-dde3-4a5b-badd-3f9137283bec/what_happens_when_you_press_alt_f4.pdf
- https://uploads.strikinglycdn.com/files/1c7e8509-8ab2-443e-8fcc-6c5803ad63f1/jenaguxirekinok.pdf
- https://uploads.strikinglycdn.com/files/c50f64df-fb72-4a41-99ad-38a82c5363c1/13979882032.pdf
- https://uploads.strikinglycdn.com/files/e98d2b74-4bfb-4b7b-933f-367e5900b8e0/12570010877.pdf
- https://uploads.strikinglycdn.com/files/a4e9fe96-7152-4f70-9637-0f52a41a5f91/tovusititatalib.pdf
- https://uploads.strikinglycdn.com/files/c7afe6bd-a4a7-40cb-bdab-c01cd7d00d2e/84780080995.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report