SUSPICIOUS — normal_5f875ae6ad605.pdf
SUSPICIOUS — normal_5f875ae6ad605.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
111fd619365f68094450e699284b4a438393943a920a184cb95e3c39af659c3d - SHA-1:
53d89f76de79a367173dbdec821c3ffec8dfbe17 - MD5:
742899f29624f731b28ad9633ae397a7 - ssdeep:
768:agGzpD6pJCbHNDrLHh759KT/6XrfW+1bvyTdEE4jTmroI:HGFWpJCbHNbru+17yREvjT0oI - TLSH:
T149316DF340A7FD4C7A8FAB039DA7155A548AD7896027D7A00488373CD5BCABE3E10A11 - Submitted as: normal_5f875ae6ad605.pdf
- File type: pdf · Size: 41377 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=atmos+power+vape+manual, https://cdn.shopify.com/s/files/1/0435/6558/0437/files/zonod.pdf, https://cdn.shopify.com/s/files/1/0429/3348/5727/files/the_visual_handbook_of_building_and_remodeling.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=atmos+power+vape+manual
- https://cdn.shopify.com/s/files/1/0435/6558/0437/files/zonod.pdf
- https://cdn.shopify.com/s/files/1/0429/3348/5727/files/the_visual_handbook_of_building_and_remodeling.pdf
- https://cdn.shopify.com/s/files/1/0459/0433/0906/files/el_cantar_del_mio_cid.pdf
- https://cdn.shopify.com/s/files/1/0440/6090/1526/files/jerry_and_harry_server_ip.pdf
- https://site-1038629.mozfiles.com/files/1038629/29483712037.pdf
- https://site-1037883.mozfiles.com/files/1037883/69692809043.pdf
- https://site-1040170.mozfiles.com/files/1040170/64866181874.pdf
- https://site-1042181.mozfiles.com/files/1042181/15155811578.pdf
- https://site-1037160.mozfiles.com/files/1037160/54069584645.pdf
- https://uploads.strikinglycdn.com/files/740bbd66-1da8-44eb-993d-778d2b8484f3/39058205401.pdf
- https://uploads.strikinglycdn.com/files/27aeb4b2-4a56-4a52-ba1a-9a69267f0e52/tatozujezaselamozo.pdf
- https://uploads.strikinglycdn.com/files/1a94968a-f229-4e5d-bc41-459e3da9b73d/panefepugorituf.pdf
- https://uploads.strikinglycdn.com/files/f85da493-9f22-44a5-b738-42310950e2d3/litador.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/xizaxamuxive.pdf
- https://lixaworone.weebly.com/uploads/1/3/1/8/131871871/teramonimavepaz.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/3e75a4e696b2f2d.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/linurigaruxox.pdf
- https://site-1044159.mozfiles.com/files/1044159/94259969088.pdf
- https://site-1038690.mozfiles.com/files/1038690/77560929823.pdf
- https://site-1040003.mozfiles.com/files/1040003/muxovofawewawu.pdf
- https://cdn.shopify.com/s/files/1/0486/1955/2926/files/tubalaliwefes.pdf
- https://cdn.shopify.com/s/files/1/0499/1290/5896/files/fun_run_2_download_hack.pdf
- https://cdn.shopify.com/s/files/1/0484/0502/0830/files/dnd_5e_javelin_build.pdf
- https://cdn.shopify.com/s/files/1/0437/9007/4016/files/juguzubewofaduzegi.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1038629.mozfiles.com
- site-1037883.mozfiles.com
- site-1040170.mozfiles.com
- site-1042181.mozfiles.com
- site-1037160.mozfiles.com
- uploads.strikinglycdn.com
- dutitujazekap.weebly.com
- lixaworone.weebly.com
- genigudepa.weebly.com
- fijojonibiw.weebly.com
- site-1044159.mozfiles.com
- site-1038690.mozfiles.com
- site-1040003.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report