SUSPICIOUS — normal_5f8e3b98209e4.pdf
SUSPICIOUS — normal_5f8e3b98209e4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
3ec83403afedb0010c9fdfb480fdffee4e6aa435bd93e212536a108376fccd60 - SHA-1:
f8ce51e7ed9e9917a560b88b6b12dfa7a1552e32 - MD5:
0f8f3b2c3831d5105f3aaec86e800310 - ssdeep:
1536:yGFApv6SDx0uq5xfytXRRIad1Q4+T/j+tWQIdn/:rFApv6SN0u1Iu1V+j+9IV - TLSH:
T16837B0F310D3DDCCB6CA5B435EB61059741ADAC93232A7944988BB6CC4BCABD6E10660 - Submitted as: normal_5f8e3b98209e4.pdf
- File type: pdf · Size: 72505 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=walkman+apk+for+android+download, https://uploads.strikinglycdn.com/files/88624c7c-dc79-4065-b147-0cafa5f23de7/evaluation_les_solides_6eme.pdf, https://uploads.strikinglycdn.com/files/1d20f369-8b9a-4e83-b759-9a94ef83efe5/vebexiredufuba.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=walkman+apk+for+android+download
- https://uploads.strikinglycdn.com/files/88624c7c-dc79-4065-b147-0cafa5f23de7/evaluation_les_solides_6eme.pdf
- https://uploads.strikinglycdn.com/files/1d20f369-8b9a-4e83-b759-9a94ef83efe5/vebexiredufuba.pdf
- https://uploads.strikinglycdn.com/files/55047b5c-0d62-4624-bf9b-b5fc95015b1e/lamijemez.pdf
- https://uploads.strikinglycdn.com/files/7ac4a8ad-c6b3-4556-88b1-e956aba6de8c/90574567768.pdf
- https://uploads.strikinglycdn.com/files/b32890c2-56db-4435-ae39-cce6ed4ceae3/96848426907.pdf
- https://cdn.shopify.com/s/files/1/0434/0505/0008/files/hey_3_next_to_normal.pdf
- https://cdn.shopify.com/s/files/1/0432/9016/5403/files/encyclopaedia_of_islam_vol_3.pdf
- https://cdn.shopify.com/s/files/1/0505/4919/4917/files/31743575925.pdf
- https://cdn.shopify.com/s/files/1/0485/7040/0928/files/aaa_western_ny_roadside_assistance.pdf
- https://uploads.strikinglycdn.com/files/1d7e5e9d-4a4b-47b0-ba18-3e35599a11a0/kiwuzopezobizekozirewutuf.pdf
- https://uploads.strikinglycdn.com/files/b0e7b4df-93da-4dc6-85c1-38e22c7304aa/31597316937.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/nukunuraki.pdf
- https://zegojipoxe.weebly.com/uploads/1/3/1/0/131069766/jujaxukupeka-lifem-katitetaz-nuvid.pdf
- https://xesaranit.weebly.com/uploads/1/3/2/6/132696194/fesivagudikud.pdf
- https://fupexorugukemig.weebly.com/uploads/1/3/0/8/130814763/bc016.pdf
- https://fimosezit.weebly.com/uploads/1/3/0/7/130775491/3a3bbaebd3c.pdf
- https://cdn-cms.f-static.net/uploads/4367297/normal_5f8e1d974b9cb.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f8d47ee16c3d.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f87b3d1797af.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- guwomenod.weebly.com
- zegojipoxe.weebly.com
- xesaranit.weebly.com
- fupexorugukemig.weebly.com
- fimosezit.weebly.com
- cdn-cms.f-static.net
- y.ir
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report