SUSPICIOUS — normal_5f9bca5a632ad.pdf
SUSPICIOUS — normal_5f9bca5a632ad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
33725a44e3abe8669e555196994411406cca2384e41216c7756fa82fa604b9ed - SHA-1:
5d2b70df328305387bf1456ff86db9fd2c98db5e - MD5:
1a7ddf14d0a5702df380a4d8b37dc47e - ssdeep:
768:l5gGzpD3y0eiUop54QIgjRcTJbv2kZIaLQpHWAYT2116KSvMMqwk52ipcSIl97jb:l6GFTYavak2Az16KSvMMqhMi2l97jb - TLSH:
T1F832BFF31157ED8C6A879F13ADBB1099108AD7886132D77459DC3A2CD0BC6AC3E80A61 - Submitted as: normal_5f9bca5a632ad.pdf
- File type: pdf · Size: 44220 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=hey+you+guys+goonies, https://cdn-cms.f-static.net/uploads/4378165/normal_5f8abd7c35d8f.pdf, https://cdn-cms.f-static.net/uploads/4384159/normal_5f8c0fda2dd2d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=hey+you+guys+goonies
- https://cdn-cms.f-static.net/uploads/4378165/normal_5f8abd7c35d8f.pdf
- https://cdn-cms.f-static.net/uploads/4384159/normal_5f8c0fda2dd2d.pdf
- https://cdn.shopify.com/s/files/1/0498/0002/0130/files/universal_unroot_download_apk.pdf
- https://cdn.shopify.com/s/files/1/0428/4101/4438/files/fifa_womens_world_cup_2020_schedule.pdf
- https://cdn-cms.f-static.net/uploads/4389797/normal_5f92738bb1360.pdf
- https://cdn.shopify.com/s/files/1/0440/6345/7432/files/samsung_4g_lte_network_extender_instructions.pdf
- https://cdn-cms.f-static.net/uploads/4420752/normal_5f99c1705d19d.pdf
- https://cdn-cms.f-static.net/uploads/4366344/normal_5f948dfba5cee.pdf
- https://cdn.shopify.com/s/files/1/0499/8463/5042/files/convertir_gramos_a_mililitros_online.pdf
- https://cdn-cms.f-static.net/uploads/4369165/normal_5f92639dd5c90.pdf
- https://cdn.shopify.com/s/files/1/0501/9146/6686/files/kaplan_lsat_coupon_code.pdf
- https://cdn.shopify.com/s/files/1/0500/2356/3434/files/blackstone_36_griddle_with_air_fryer.pdf
- https://s3.amazonaws.com/tofizo/zulilidikireduris.pdf
- https://s3.amazonaws.com/xunilukegez/handley_high_school_winchester_va.pdf
- https://cdn.shopify.com/s/files/1/0499/7772/0984/files/zemijusejijomutozafuwe.pdf
- https://cdn.shopify.com/s/files/1/0483/4295/8231/files/keras_lstm_tutorial.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report