SUSPICIOUS — normal_5f8d3fd7cf3e6.pdf
SUSPICIOUS — normal_5f8d3fd7cf3e6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
22b0985c5ae84eded091a13ab23458ddcfb2807f7aad7b9b05df8a1ed70a0b51 - SHA-1:
7d9ce786a85cd71dd1cbd27839975feb88285295 - MD5:
49a5926de9313c82d0c9a4df0401ea14 - ssdeep:
768:5gGzpD0ppPhFMAZnK3vs91wvXFfFkM3kZQ2Oo+gtQMl:6GFoppF1w/Fl1gtQY - TLSH:
T173306BF350A7ED8C79879F03AAAA295D9089D74CA03297A044D8772CC4BC7BC7F50865 - Submitted as: normal_5f8d3fd7cf3e6.pdf
- File type: pdf · Size: 37439 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=autodesk+apk+download+apkpure, https://uploads.strikinglycdn.com/files/e6875a42-95cd-4c6d-87e7-44bbf723f04a/2920359727.pdf, https://uploads.strikinglycdn.com/files/4043a6b4-358a-486a-857f-5aa0e42c6815/35768243724.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=autodesk+apk+download+apkpure
- https://uploads.strikinglycdn.com/files/e6875a42-95cd-4c6d-87e7-44bbf723f04a/2920359727.pdf
- https://uploads.strikinglycdn.com/files/4043a6b4-358a-486a-857f-5aa0e42c6815/35768243724.pdf
- https://uploads.strikinglycdn.com/files/13a9fb07-4b5c-42ab-b4ea-e3e3e1ca9832/xexujaposuzeriruso.pdf
- https://uploads.strikinglycdn.com/files/a57866e9-6b9b-44a2-a8f4-39158141c7e7/ledomexevugivurinu.pdf
- https://uploads.strikinglycdn.com/files/c3aefd3a-46fa-44f3-b124-30ebf9ae30ea/21291637819.pdf
- https://uploads.strikinglycdn.com/files/41f17f9b-32ec-472a-8b2e-76af50c7f70a/tabla_de_nexos_y_conectores.pdf
- https://uploads.strikinglycdn.com/files/6879181f-6044-4579-96d0-5e3effa0df02/33988131191.pdf
- https://uploads.strikinglycdn.com/files/54f3d92e-013b-4917-ba20-6150c5eb0857/93719379916.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f873c41551b3.pdf
- https://cdn-cms.f-static.net/uploads/4371814/normal_5f886ed794b54.pdf
- https://cdn-cms.f-static.net/uploads/4368972/normal_5f882167d4637.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/belapigojat.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/xupabozividefirupax.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/2f0e95c1e.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f87b047c0db9.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f87d8e6ac38e.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8a6124742db.pdf
- https://cdn-cms.f-static.net/uploads/4372740/normal_5f8890dc094d1.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/5acab582ad41.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/523a67add.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- guwomenod.weebly.com
- jukafubu.weebly.com
- jezaxegare.weebly.com
- keniwuki.weebly.com
- xojerajap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report