SUSPICIOUS — normal_5f87672d42ebe.pdf
SUSPICIOUS — normal_5f87672d42ebe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
3e3d829930cf34316a975f1632903cfad3778aafe1ab68831b6c8c099d80ade2 - SHA-1:
61aabc8c8b226be470ad5eb7f18cb47d030de4c3 - MD5:
7fe8e40ab888195e2264fffe59b7f12c - ssdeep:
768:sgGzpD83pS3GGP5mXelGlPzY17udPxVIkCAT9lZsviVHPg619HsWQdEKrFTSK+uT:pGFo3pxVaGxVIkCAT9lZswVcWiEK1SKf - TLSH:
T14E339FF31097EE8C7B8EAB039EAB015D605ED78C6033A6A04489372DD5BC9FD6E10591 - Submitted as: normal_5f87672d42ebe.pdf
- File type: pdf · Size: 47660 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=manual+lawn+edger+tool+menards, https://site-1043096.mozfiles.com/files/1043096/96854423648.pdf, https://site-1042671.mozfiles.com/files/1042671/35088677367.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=manual+lawn+edger+tool+menards
- https://site-1043096.mozfiles.com/files/1043096/96854423648.pdf
- https://site-1042671.mozfiles.com/files/1042671/35088677367.pdf
- https://site-1043353.mozfiles.com/files/1043353/zodazedakadopap.pdf
- https://cdn.shopify.com/s/files/1/0499/5088/4008/files/81279025790.pdf
- https://cdn.shopify.com/s/files/1/0433/1782/1605/files/71642902991.pdf
- https://cdn.shopify.com/s/files/1/0497/4903/3114/files/10063853775.pdf
- https://cdn.shopify.com/s/files/1/0431/1505/3213/files/mobagediju.pdf
- https://site-1042198.mozfiles.com/files/1042198/dalesozegixasasatipu.pdf
- https://site-1037124.mozfiles.com/files/1037124/zuxabosoxevejinezokuwedi.pdf
- https://cdn.shopify.com/s/files/1/0479/8237/9164/files/cobit_5_processes_list.pdf
- https://cdn.shopify.com/s/files/1/0436/3816/1561/files/kyou_no_asuka_show_kissanime.pdf
- https://uploads.strikinglycdn.com/files/caea4e1c-950a-41b3-8f53-ffd976866705/64982122419.pdf
- https://uploads.strikinglycdn.com/files/847552b5-0eaf-4100-8d2c-0a36b25b899d/44293058737.pdf
- https://uploads.strikinglycdn.com/files/9df71023-e006-4a70-a10b-e489d4ec8493/vowowagakefoti.pdf
- https://uploads.strikinglycdn.com/files/68b4bca1-838d-47e0-be72-709b9c36deb0/66641927539.pdf
- https://uploads.strikinglycdn.com/files/d3df40ea-da8d-4882-ae34-8369f1ab69ee/kevezirinin.pdf
- https://uploads.strikinglycdn.com/files/9bdca83b-35f9-4bde-a3bd-05bc8f1475a5/2486492391.pdf
- https://uploads.strikinglycdn.com/files/f919489b-d99b-4f80-b817-d89953a8b083/bowumubexopitu.pdf
- https://uploads.strikinglycdn.com/files/69138006-b30f-4cb5-b821-2145d2c6f52e/63313248232.pdf
- https://uploads.strikinglycdn.com/files/865505e1-9737-47a2-b8d2-0de9aaa83db9/baranojused.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- site-1043096.mozfiles.com
- site-1042671.mozfiles.com
- site-1043353.mozfiles.com
- cdn.shopify.com
- site-1042198.mozfiles.com
- site-1037124.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report