SUSPICIOUS — normal_5f88669182cc4.pdf
SUSPICIOUS — normal_5f88669182cc4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
56a76b672cf932f696797cd4953e2a0975f26c3cae1d7446c2e863de3f4e2131 - SHA-1:
7ec7dd7e74d9842d4566d7405d76231c2e0da77e - MD5:
3b241237b06671caf341e64797946b28 - ssdeep:
768:ggGzpD1pO2ViNRr3c4RT40WKpSJ2dd54gCJlgnozK82QMwehXQKEeA:tGFBpOmZnnX29wehXQKEeA - TLSH:
T187319EF324E7EC9C7AC69B13ACAA116D2089D74C623397A0548C772CE4BC6BD7E10950 - Submitted as: normal_5f88669182cc4.pdf
- File type: pdf · Size: 42051 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=hurom+juice+recipes+pdf, https://cdn-cms.f-static.net/uploads/4365627/normal_5f87141d950ff.pdf, https://cdn-cms.f-static.net/uploads/4365635/normal_5f87049821a38.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=hurom+juice+recipes+pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f87141d950ff.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f87049821a38.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f8835269522e.pdf
- https://cdn-cms.f-static.net/uploads/4370996/normal_5f886262c7046.pdf
- https://uploads.strikinglycdn.com/files/041ec1e9-e447-403e-8ca8-50471379447c/juzudasak.pdf
- https://uploads.strikinglycdn.com/files/f96e6b9a-9ba1-4d09-902d-88813f6563ae/jibomuperorupaxode.pdf
- https://uploads.strikinglycdn.com/files/0caa401f-989e-457a-9cef-8a861bbb042f/46048762816.pdf
- https://uploads.strikinglycdn.com/files/eb328756-b98c-4d3b-bcce-4e223b16843d/82590231646.pdf
- https://uploads.strikinglycdn.com/files/9bc3bc23-9bbb-4c25-88c0-e08123543da8/38353240932.pdf
- https://uploads.strikinglycdn.com/files/5e86dc4c-e64b-47ec-a122-5be05636d259/pojusiwiditogaxuj.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/dukemapa.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/xumavefodomagaw_vanogufuwarapo_nopokakakamu.pdf
- https://xojisige.weebly.com/uploads/1/3/1/6/131637148/lepubewopawipozosofa.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f8701041dcff.pdf
- https://cdn-cms.f-static.net/uploads/4369503/normal_5f885c66afccc.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f8707fe83c5f.pdf
- https://cdn.shopify.com/s/files/1/0488/3398/6725/files/sta_rite_pool_heater_troubleshooting_guide.pdf
- https://cdn.shopify.com/s/files/1/0499/9151/6310/files/4288998823.pdf
- https://cdn.shopify.com/s/files/1/0429/4646/1855/files/energy_conservation_in_waste_heat_recovery_system.pdf
- https://cdn.shopify.com/s/files/1/0433/6828/4319/files/48735171405.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- nudojafobedem.weebly.com
- taxajadotediru.weebly.com
- xojisige.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report