SUSPICIOUS — normal_5f8760e095a00.pdf
SUSPICIOUS — normal_5f8760e095a00.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
13850c48fe6ac25802479cba0408a67a8b6bb8b46b2ad480bd7ce7d73f4cea24 - SHA-1:
fbb77f3bb8fb6437fa832c0238a77490baf5f814 - MD5:
5d4cea9d1a5b45076b003c7758a38263 - ssdeep:
768:7gGzpDDpucu0L/nhEye3VNJ2xFlESMNGGxg1W7/i5sWe5x+RgCIhENW9b0aJQZQs:EGF/pRuArGS4gsquQEhe+12h30jNiT - TLSH:
T1E235AEF36597DD4CBA8B8B83ADDB255A6089C28C7237D75054CC262CD5BC2BDBE00960 - Submitted as: normal_5f8760e095a00.pdf
- File type: pdf · Size: 60298 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=accounting+terms+pdf+free+download, https://cdn-cms.f-static.net/uploads/4366041/normal_5f871a670ad3f.pdf, https://cdn-cms.f-static.net/uploads/4366050/normal_5f8720d253ef2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=accounting+terms+pdf+free+download
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f871a670ad3f.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_5f8720d253ef2.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f8744fd5e33c.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f870264cd2ca.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f874c6994e6e.pdf
- https://cdn.shopify.com/s/files/1/0428/4927/1975/files/wall_mounted_fish_bowl_with_oxygen_pump.pdf
- https://cdn.shopify.com/s/files/1/0434/4319/1960/files/four_primary_components_of_the_strategic_management_process.pdf
- https://cdn.shopify.com/s/files/1/0496/3690/1013/files/audiovision_music_player_premium_apk.pdf
- https://cdn.shopify.com/s/files/1/0437/2440/6933/files/giant_car_bows_hobby_lobby.pdf
- https://cdn.shopify.com/s/files/1/0503/6575/9675/files/zojitojokar.pdf
- https://uploads.strikinglycdn.com/files/3ce7a710-692d-45a7-b803-939f2bfb108f/sodixofigotejeteb.pdf
- https://uploads.strikinglycdn.com/files/ec851819-b2e4-4e51-8c54-c4621d2466f0/ledimesadigeteluxakeliseg.pdf
- https://uploads.strikinglycdn.com/files/ef6913cc-5f07-4a0d-a074-5f634b8284dd/32929643876.pdf
- https://uploads.strikinglycdn.com/files/3036e0b8-574a-42a3-a451-64b4a9c42f05/makike.pdf
- https://uploads.strikinglycdn.com/files/db518d8b-c1cb-4e05-abd6-9a11333ef6a7/duwuxosupogidebadegafi.pdf
- https://cdn.shopify.com/s/files/1/0440/3943/8501/files/poxagalesax.pdf
- https://cdn.shopify.com/s/files/1/0437/7290/3578/files/tunotimom.pdf
- https://cdn.shopify.com/s/files/1/0486/0788/7518/files/92682230403.pdf
- https://cdn.shopify.com/s/files/1/0430/3277/2757/files/moon_phases_quizlet_brainpop.pdf
- https://cdn.shopify.com/s/files/1/0498/3455/7602/files/ft-7900r_for_sale.pdf
- https://site-1043220.mozfiles.com/files/1043220/gikulonoj.pdf
- https://site-1040350.mozfiles.com/files/1040350/lozodopugifukujekex.pdf
- https://site-1040136.mozfiles.com/files/1040136/43523900894.pdf
- https://site-1041782.mozfiles.com/files/1041782/16360567182.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1043220.mozfiles.com
- site-1040350.mozfiles.com
- site-1040136.mozfiles.com
- site-1041782.mozfiles.com
- site-1039002.mozfiles.com
- vekejuritikoj.weebly.com
- rivisoni.weebly.com
- jakedekokobara.weebly.com
- xojerajap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report