SUSPICIOUS — normal_5f8fa05c69d83.pdf
SUSPICIOUS — normal_5f8fa05c69d83.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
106a77c1233af7ec9f0ad99d9de9c9e9ecd6ad17da54d2df92b83793b0b32c62 - SHA-1:
3fe298e8e5d086192fd652f9a4901dc3d3935d6f - MD5:
965a325add80887c67e140a7637582b1 - ssdeep:
768:agGzpD/pSPTBdkzg6dPsgJETRm1lbZJ53cVM+257U7Ebi2Y3APoByzZrCyp9qXKX:HGFLpt4Ybi2YwPoBy15SXNJI - TLSH:
T182317CF750DBED8D7A878F13ADAF1619514AC688A2379750045C372CC2BC67DBE20861 - Submitted as: normal_5f8fa05c69d83.pdf
- File type: pdf · Size: 42198 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=letter+m+worksheet+for+toddlers, https://cdn.shopify.com/s/files/1/0478/0372/8031/files/giwasajudixela.pdf, https://cdn.shopify.com/s/files/1/0432/3042/9352/files/33602292037.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=letter+m+worksheet+for+toddlers
- https://cdn.shopify.com/s/files/1/0478/0372/8031/files/giwasajudixela.pdf
- https://cdn.shopify.com/s/files/1/0432/3042/9352/files/33602292037.pdf
- https://cdn.shopify.com/s/files/1/0495/2018/1414/files/zupewafajurev.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/how_to_upload_image_using_retrofit_android.pdf
- https://cdn.shopify.com/s/files/1/0488/4080/2469/files/gadise.pdf
- https://cdn.shopify.com/s/files/1/0499/2077/0237/files/codigo_procesal_penal_colombiano.pdf
- https://cdn.shopify.com/s/files/1/0504/2910/0230/files/gotiveliz.pdf
- https://cdn.shopify.com/s/files/1/0433/8306/2678/files/the_scarlet_letter_setting_essay.pdf
- https://cdn.shopify.com/s/files/1/0436/3137/8592/files/84960728528.pdf
- https://cdn.shopify.com/s/files/1/0478/2532/2143/files/javobowafuri.pdf
- https://cdn.shopify.com/s/files/1/0440/4586/1029/files/jarafaxisapunelalizidora.pdf
- https://cdn.shopify.com/s/files/1/0482/6716/5860/files/83565896690.pdf
- https://cdn.shopify.com/s/files/1/0503/8309/3910/files/rosary_joyful_mysteries.pdf
- https://cdn.shopify.com/s/files/1/0493/0886/0575/files/a-check_global_drug_test.pdf
- https://pezopipowom.weebly.com/uploads/1/3/1/4/131406060/5351011.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5648329.pdf
- https://pagofere.weebly.com/uploads/1/3/1/3/131398194/tubowa-zizuxugitelilu-dobaw.pdf
- https://gozofuma.weebly.com/uploads/1/3/0/8/130874065/541746.pdf
- https://kokexofagisukop.weebly.com/uploads/1/3/2/7/132710589/wixigasovigemoximete.pdf
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f89b0a6e47fb.pdf
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f8b71e039302.pdf
- https://cdn-cms.f-static.net/uploads/4383916/normal_5f8beaa879d19.pdf
- https://cdn-cms.f-static.net/uploads/4368503/normal_5f88d573a083d.pdf
- https://kidunaxu.weebly.com/uploads/1/3/1/4/131437100/59a8e5ae677b34a.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- pezopipowom.weebly.com
- fijojonibiw.weebly.com
- pagofere.weebly.com
- gozofuma.weebly.com
- kokexofagisukop.weebly.com
- cdn-cms.f-static.net
- kidunaxu.weebly.com
- guwomenod.weebly.com
- povutepumik.weebly.com
- gimejexoxixaza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report