SUSPICIOUS — normal_5f87466c8363c.pdf
SUSPICIOUS — normal_5f87466c8363c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
6b341983daec29a668cce22bf80503f5e5e79ed8cd7caa8aee59a29a7b198cf1 - SHA-1:
dcd49c5c610f40dc39da744d6b8ab1d9a71a4443 - MD5:
f7a4fe8ee1d38c1f07c9b9b55f9d0fd9 - ssdeep:
768:KgGzpDaesIy9+ve7We0Y3qGNFKmsLVXu+IOeWDuixHjUg+zygsCffT/0hw:XGF+eywVXuqHug+zl9fT0hw - TLSH:
T1C9338DF35067DD8C7A876B03ADE70155658ECB8C52329BB0448C6B2CD9BC6BCBE11921 - Submitted as: normal_5f87466c8363c.pdf
- File type: pdf · Size: 47960 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=arabian+nights+book+pdf+free+download, https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/7885719.pdf, https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/5650151.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=arabian+nights+book+pdf+free+download
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/7885719.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/5650151.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/mezevoxinokimuwamibu.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/vezoza.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/3409757.pdf
- https://cdn.shopify.com/s/files/1/0434/9178/6918/files/35058329523.pdf
- https://cdn.shopify.com/s/files/1/0498/1194/7682/files/xaxegijixu.pdf
- https://cdn.shopify.com/s/files/1/0499/3928/4126/files/komurunonigunuwajase.pdf
- https://cdn.shopify.com/s/files/1/0482/9462/5441/files/antigone_family_tree.pdf
- https://cdn.shopify.com/s/files/1/0475/9345/5772/files/91038286842.pdf
- https://cdn.shopify.com/s/files/1/0496/4948/3939/files/39125746551.pdf
- https://cdn.shopify.com/s/files/1/0482/7414/5441/files/40935767126.pdf
- https://cdn.shopify.com/s/files/1/0433/7981/8661/files/lofebuxomulutosajupuxam.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f87110f54319.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f873e5b6c01f.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f872ea97a3af.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f870ee590070.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f871a6764d7e.pdf
- https://site-1039721.mozfiles.com/files/1039721/21628393863.pdf
- https://site-1042779.mozfiles.com/files/1042779/70120032243.pdf
- https://site-1043539.mozfiles.com/files/1043539/82812271509.pdf
- https://site-1039735.mozfiles.com/files/1039735/darejegovof.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- keniwuki.weebly.com
- jatorogerujew.weebly.com
- xojerajap.weebly.com
- jukafubu.weebly.com
- guwomenod.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1039721.mozfiles.com
- site-1042779.mozfiles.com
- site-1043539.mozfiles.com
- site-1039735.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report