SUSPICIOUS — normal_5f88b4b5f08ea.pdf
SUSPICIOUS — normal_5f88b4b5f08ea.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
1616e9396a7281c2aa868c719c63b05acab57ffd8493fbbe27af370a8433ecae - SHA-1:
1d2ee145f195bf2770c3a0a664766b502f6636d6 - MD5:
8bb4706e4639ecbd12356a121d8feb45 - ssdeep:
1536:pGFkp+fhrM/lB4NquCVg+gf/WyjaZavk22:8FkpKhrA4NquCujf5Aavc - TLSH:
T118339EF350A7DD4C7A8FBF83AEA61058614AC78D313297A04588672CD4BC6FDAF10A51 - Submitted as: normal_5f88b4b5f08ea.pdf
- File type: pdf · Size: 50518 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=kobane+calling+english+pdf, https://site-1045390.mozfiles.com/files/1045390/96844422062.pdf, https://site-1041212.mozfiles.com/files/1041212/pirowidonekusuwezi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=kobane+calling+english+pdf
- https://site-1045390.mozfiles.com/files/1045390/96844422062.pdf
- https://site-1041212.mozfiles.com/files/1041212/pirowidonekusuwezi.pdf
- https://site-1037843.mozfiles.com/files/1037843/zipinobepezamiroginog.pdf
- https://site-1043793.mozfiles.com/files/1043793/27624492917.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f86f4d598d42.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f872d6ee9e65.pdf
- https://site-1039279.mozfiles.com/files/1039279/54754844940.pdf
- https://site-1037866.mozfiles.com/files/1037866/7886879158.pdf
- https://site-1043087.mozfiles.com/files/1043087/91119987011.pdf
- https://site-1040426.mozfiles.com/files/1040426/getovifune.pdf
- https://site-1038597.mozfiles.com/files/1038597/88690687461.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f870f9043b17.pdf
- https://cdn-cms.f-static.net/uploads/4369308/normal_5f87c7e65a798.pdf
- https://cdn-cms.f-static.net/uploads/4367013/normal_5f873f22e8829.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f874b0c39ba8.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f875d40d5d7c.pdf
- https://cdn.shopify.com/s/files/1/0436/4078/3008/files/latin_for_homeostasis.pdf
- https://cdn.shopify.com/s/files/1/0480/6190/7108/files/xenaxube.pdf
- https://cdn.shopify.com/s/files/1/0427/8861/8396/files/what_is_m1_in_ironmania.pdf
- https://cdn.shopify.com/s/files/1/0496/7451/8691/files/tubemate_pro_apk_free_download.pdf
- https://cdn.shopify.com/s/files/1/0266/9346/8338/files/victorian_chaise_lounge.pdf
- https://uploads.strikinglycdn.com/files/52ea70fb-8408-433c-83e6-df1ca8d7b44c/26997393505.pdf
- https://uploads.strikinglycdn.com/files/86eccd37-f5f0-47fa-aec9-d082d8282a71/digasuvaxisimawawewedono.pdf
- https://uploads.strikinglycdn.com/files/ff8551ab-63d9-4166-9d98-804ea0b7490a/65941566752.pdf
Embedded domains
- ggtraff.ru
- site-1045390.mozfiles.com
- site-1041212.mozfiles.com
- site-1037843.mozfiles.com
- site-1043793.mozfiles.com
- cdn-cms.f-static.net
- site-1039279.mozfiles.com
- site-1037866.mozfiles.com
- site-1043087.mozfiles.com
- site-1040426.mozfiles.com
- site-1038597.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report