SUSPICIOUS — normal_5f872f9ea99c4.pdf
SUSPICIOUS — normal_5f872f9ea99c4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
44607b0ca6b27c29496464bf650a6acf255808f7ca8374ee459642b4a243f6dd - SHA-1:
1038695930a55ffc6bdeaf3d36e08ce6b8d7907d - MD5:
4780fc0fa7828c4f014f8cd8c365746c - ssdeep:
768:RmgGzpDyp3pC3pQvl7iQIpUS3XH/av6Tri2q6ho3WOihd2YCcQmJp0mam8sJvrLE:xGF+pZOb/nN0vNabJCmQsJv2YOj8u - TLSH:
T16A329EF76057FC4D7A8E9B03AE9B109DA049D3889137AA60458C6B3CD57C6FD3E009A1 - Submitted as: normal_5f872f9ea99c4.pdf
- File type: pdf · Size: 45456 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=pre+settlement+app+android, https://cdn.shopify.com/s/files/1/0434/4040/6684/files/account_action_required_google.pdf, https://cdn.shopify.com/s/files/1/0266/8124/5870/files/garisinevolarepimuvu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=pre+settlement+app+android
- https://cdn.shopify.com/s/files/1/0434/4040/6684/files/account_action_required_google.pdf
- https://cdn.shopify.com/s/files/1/0266/8124/5870/files/garisinevolarepimuvu.pdf
- https://cdn.shopify.com/s/files/1/0483/3447/1318/files/selling_for_dummies_tom_hopkins_download.pdf
- https://cdn.shopify.com/s/files/1/0501/5833/8210/files/devumutezoxivi.pdf
- https://cdn.shopify.com/s/files/1/0432/1738/7682/files/88815325016.pdf
- https://site-1043759.mozfiles.com/files/1043759/html_attribute_style_guide.pdf
- https://site-1036951.mozfiles.com/files/1036951/darizixarejexujinulanapav.pdf
- https://site-1036874.mozfiles.com/files/1036874/77093268111.pdf
- https://site-1039693.mozfiles.com/files/1039693/detelosej.pdf
- https://site-1044020.mozfiles.com/files/1044020/97855827722.pdf
- https://cdn.shopify.com/s/files/1/0435/2599/6698/files/square_terracotta_pots_adelaide.pdf
- https://cdn.shopify.com/s/files/1/0484/6554/3329/files/zigebelizojunate.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/zikarab.pdf
- https://site-1041846.mozfiles.com/files/1041846/bebefafixajipekam.pdf
- https://site-1042830.mozfiles.com/files/1042830/pizuwi.pdf
- https://cdn.shopify.com/s/files/1/0430/7619/0361/files/amoled_pro_wallpapers_apk_download_free.pdf
- https://cdn.shopify.com/s/files/1/0493/3894/1599/files/charge_static_electricity_answers.pdf
- https://cdn.shopify.com/s/files/1/0496/4699/3557/files/89308340019.pdf
- https://cdn.shopify.com/s/files/1/0431/5178/6145/files/memorex_cd_clock_radio_with_dual_alarm_mc2864_manual.pdf
- https://cdn.shopify.com/s/files/1/0430/3526/3130/files/11669527737.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1043759.mozfiles.com
- site-1036951.mozfiles.com
- site-1036874.mozfiles.com
- site-1039693.mozfiles.com
- site-1044020.mozfiles.com
- dutitujazekap.weebly.com
- site-1041846.mozfiles.com
- site-1042830.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report