SUSPICIOUS — normal_5f874b54b84d2.pdf
SUSPICIOUS — normal_5f874b54b84d2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
6a4d8bc286308854a920c02563e1fcafa9ede6dc044ad6d35259d01d2e932af6 - SHA-1:
54f06e4e00ff83adf778e9f4c4e5bbe48ddf860e - MD5:
4f3c492b39ff5b5c5c0c873b1b9c46cb - ssdeep:
768:FgGzpDJps3vRIg2FU++E99rQ2Qi5UUfFuRBV5eM4PDuR2LdkHlOv4AZ2TbNvNitC:WGFFpjUUNUE9EGd+lc4AZ2TJvNitY5 - TLSH:
T18A328EF350A7EC8C768F6B139DBB0169A08AD78C60229790548C772CD17CAFE7E11661 - Submitted as: normal_5f874b54b84d2.pdf
- File type: pdf · Size: 46486 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=area+and+perimeter+of+square+worksheet, https://uploads.strikinglycdn.com/files/44d1fd87-c20d-4887-823b-e2b0385d2723/jasurod.pdf, https://uploads.strikinglycdn.com/files/a8481241-71ed-461c-87b9-7184fa70ca95/soxaratisebumigukaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=area+and+perimeter+of+square+worksheet
- https://uploads.strikinglycdn.com/files/44d1fd87-c20d-4887-823b-e2b0385d2723/jasurod.pdf
- https://uploads.strikinglycdn.com/files/a8481241-71ed-461c-87b9-7184fa70ca95/soxaratisebumigukaf.pdf
- https://uploads.strikinglycdn.com/files/603a6a1d-655f-4f8e-a657-a2574115119c/23772114210.pdf
- https://uploads.strikinglycdn.com/files/97c660fb-d230-414a-8a25-a3cc0b0e90e4/pivixoguda.pdf
- https://uploads.strikinglycdn.com/files/b4dd7ce2-0796-4216-91fe-34856fc4feb9/58420921908.pdf
- https://uploads.strikinglycdn.com/files/dfe77f78-884e-45e9-8df8-7d648f4e4ecc/wafefot.pdf
- https://uploads.strikinglycdn.com/files/80b57879-bf0d-420b-87c3-49e8caaccb02/nedetivasom.pdf
- https://uploads.strikinglycdn.com/files/5f004969-a7db-4fd1-bded-57ede3862d58/dejatexo.pdf
- https://cdn.shopify.com/s/files/1/0432/6113/2968/files/55660323443.pdf
- https://cdn.shopify.com/s/files/1/0437/8004/7010/files/atari_7800_roms_retropie.pdf
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f870e42872c0.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f870832cb2b3.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f873349f02fb.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f873c156d3ca.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f86ffd811937.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f86f9e1bc45d.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f8709c6bd42b.pdf
- https://cdn-cms.f-static.net/uploads/4365552/normal_5f8706e3e1bd8.pdf
- https://cdn.shopify.com/s/files/1/0496/5023/7604/files/cannot_print_secured_document.pdf
- https://cdn.shopify.com/s/files/1/0496/6835/8301/files/ain_soph_aur_mudvayne.pdf
- https://cdn.shopify.com/s/files/1/0499/3574/5186/files/dakuwepumefit.pdf
- https://cdn.shopify.com/s/files/1/0438/2310/4160/files/soccer_stars_hack_apk_android_1.pdf
- https://cdn.shopify.com/s/files/1/0430/4135/7973/files/haier_air_conditioner_parts_near_me.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report