SUSPICIOUS — normal_5f8bf6bd14450.pdf
SUSPICIOUS — normal_5f8bf6bd14450.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
086696662097a1b56be56685773f79907398d93104f46220d83e2124c6795111 - SHA-1:
82e4a184b7161c718434bd5a8844b0ff0b95e88f - MD5:
cd9930a4381618cfe775954437509efa - ssdeep:
768:GgGzpDpp8grQd7+2eIdE32QlEH9rZpw+QAsDYd0SS9uK90TQOkP4Gp1mUL6:TGFNpD2tHPdZquKikPZDmS6 - TLSH:
T15C327DF360A7ED4C7A8F5B03ADEA11596489D34DB127D75044CC762CC87CAAD2F10962 - Submitted as: normal_5f8bf6bd14450.pdf
- File type: pdf · Size: 47118 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=peugeot+3008+egypt+pdf, https://uploads.strikinglycdn.com/files/2ff52f2e-4f55-4fef-9811-74c407b1bdaf/gagevadasubu.pdf, https://uploads.strikinglycdn.com/files/ebe73157-e196-4101-a5ac-01ef9c805b11/21058879073.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=peugeot+3008+egypt+pdf
- https://uploads.strikinglycdn.com/files/2ff52f2e-4f55-4fef-9811-74c407b1bdaf/gagevadasubu.pdf
- https://uploads.strikinglycdn.com/files/ebe73157-e196-4101-a5ac-01ef9c805b11/21058879073.pdf
- https://uploads.strikinglycdn.com/files/10c692cd-e21b-462a-9475-9ceb7b49b263/nexigefa.pdf
- https://uploads.strikinglycdn.com/files/f487ce4f-32d0-4feb-ad55-04b4321fbded/dakopuseb.pdf
- https://uploads.strikinglycdn.com/files/4d93cf61-0461-402a-b705-af408c593be7/libro_de_50_sombras_mas_oscuras_de_grey.pdf
- https://cdn-cms.f-static.net/uploads/4369512/normal_5f87bbbdcae0a.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f86fa8753dc3.pdf
- https://cdn-cms.f-static.net/uploads/4367944/normal_5f8908d489e03.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f87a0477a5a0.pdf
- https://cdn-cms.f-static.net/uploads/4366660/normal_5f873b40ac659.pdf
- https://cdn.shopify.com/s/files/1/0468/1580/5594/files/george_j._mitchell_epstein.pdf
- https://cdn.shopify.com/s/files/1/0499/5865/0009/files/78594605434.pdf
- https://cdn.shopify.com/s/files/1/0497/4936/0793/files/wheelchair_guidelines_nhs.pdf
- https://uploads.strikinglycdn.com/files/69a2a05a-f408-4c19-b9f7-daab69c2ac21/870872303.pdf
- https://uploads.strikinglycdn.com/files/c08a3c67-5633-4838-b1a5-c60c7ecc9fc7/bitawexopotugutobofinu.pdf
- https://uploads.strikinglycdn.com/files/12c9d76f-8ef5-4468-a917-d5667ede69a7/punawalitogunidiw.pdf
- https://penulikadima.weebly.com/uploads/1/3/1/4/131482887/66cfa.pdf
- https://bizetuxerupa.weebly.com/uploads/1/3/0/8/130873791/e4af33a3a.pdf
- https://wuwuleli.weebly.com/uploads/1/3/1/3/131398564/dezal.pdf
- https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/saganan.pdf
- https://xifobosakup.weebly.com/uploads/1/3/2/8/132815359/xigin_folemusun_zuvilodipovupuz.pdf
- https://cdn-cms.f-static.net/uploads/4375209/normal_5f89deff96d26.pdf
- https://cdn-cms.f-static.net/uploads/4369315/normal_5f87ac2972652.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f8726b1ca632.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- penulikadima.weebly.com
- bizetuxerupa.weebly.com
- wuwuleli.weebly.com
- vikumeniwexawud.weebly.com
- xifobosakup.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report