SUSPICIOUS — normal_5f878b8d8419b.pdf
SUSPICIOUS — normal_5f878b8d8419b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
3e2a54936732306f15dfb4d6e513370a27a1c2b06de0d711904305bc1af9b59a - SHA-1:
5313d3a9195bc95059b7d13bf284b79b6b8ead61 - MD5:
feb8718597c7dab6f52bb56438fbc71a - ssdeep:
1536:IGFIedztZxJYC15rjT2wDFJuSyu+ku96voK:lFIep5Hr3BzRy7ku96V - TLSH:
T143339DF31097EC8D7A8B9B53BDE61459200AD78C6237E7A0199C376CC56C67DBE10A10 - Submitted as: normal_5f878b8d8419b.pdf
- File type: pdf · Size: 50444 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=exercises+with+verb+can+pdf, https://cdn.shopify.com/s/files/1/0501/3372/9445/files/hung_gar_kung_fu_stances.pdf, https://cdn.shopify.com/s/files/1/0486/9013/5190/files/8332189600.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=exercises+with+verb+can+pdf
- https://cdn.shopify.com/s/files/1/0501/3372/9445/files/hung_gar_kung_fu_stances.pdf
- https://cdn.shopify.com/s/files/1/0486/9013/5190/files/8332189600.pdf
- https://cdn.shopify.com/s/files/1/0266/9291/1298/files/7797077408.pdf
- https://cdn.shopify.com/s/files/1/0477/3730/7292/files/lakonufotugadel.pdf
- https://cdn.shopify.com/s/files/1/0501/1062/8008/files/jemoxuworekovotuluwewa.pdf
- https://cdn.shopify.com/s/files/1/0481/6492/9689/files/82546344738.pdf
- https://cdn.shopify.com/s/files/1/0485/1109/0850/files/minecraft_pe_1.11_4.2_apk_con_licencia.pdf
- https://cdn.shopify.com/s/files/1/0482/6736/2468/files/beautiful_outlaw_download.pdf
- https://cdn.shopify.com/s/files/1/0494/4936/9759/files/chuck_e_cheese_birthday_song_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0435/2573/4552/files/25341191651.pdf
- https://cdn.shopify.com/s/files/1/0501/7547/5872/files/chili_cheese_fritos_corn_salad.pdf
- https://cdn.shopify.com/s/files/1/0429/2896/3747/files/game_of_thrones_office_pool_download.pdf
- https://cdn.shopify.com/s/files/1/0428/8934/7228/files/67470150511.pdf
- https://cdn.shopify.com/s/files/1/0433/9816/8725/files/dork_diaries_8_free.pdf
- https://cdn.shopify.com/s/files/1/0428/6201/8716/files/56279606250.pdf
- https://cdn-cms.f-static.net/uploads/4367004/normal_5f87300ef3418.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f87089b227d3.pdf
- https://cdn.shopify.com/s/files/1/0477/0974/9407/files/vizio_sb3851-c0_subwoofer.pdf
- https://cdn.shopify.com/s/files/1/0499/3908/7514/files/44517610551.pdf
- https://cdn.shopify.com/s/files/1/0431/6453/2900/files/35778158782.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report