SUSPICIOUS — normal_5f872c78a87fd.pdf
SUSPICIOUS — normal_5f872c78a87fd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6be8b8c06537254514738e72f0096ecfb2e8b06befab2aec42d159c72c58a987 - SHA-1:
6d0db2795055567e50a7a9278b1020ccf6a534a5 - MD5:
c8a03d81f63ae9a7431654cad20df3d6 - ssdeep:
768:CgGzpDiplCzipzF7D0pgYE6+p8e0cjLUwWapZQO5VAe1tEzre+B:fGF2pGJeHWapn5qejEza+B - TLSH:
T19F338EF360A7FD8C7E8B9B13ADE6015C908AC7CC6127D7505888262DD4BC6FDAE00A51 - Submitted as: normal_5f872c78a87fd.pdf
- File type: pdf · Size: 48202 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=rights+of+prisoners+of+war+pdf, https://uploads.strikinglycdn.com/files/c15b5a62-9dbf-4bce-96e0-5ae1f3d9954b/36863308871.pdf, https://uploads.strikinglycdn.com/files/dcfe647b-abca-489c-889f-555670373c4e/renoluripuwinumafarer.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=rights+of+prisoners+of+war+pdf
- https://uploads.strikinglycdn.com/files/c15b5a62-9dbf-4bce-96e0-5ae1f3d9954b/36863308871.pdf
- https://uploads.strikinglycdn.com/files/dcfe647b-abca-489c-889f-555670373c4e/renoluripuwinumafarer.pdf
- https://uploads.strikinglycdn.com/files/2da1b216-b5c7-4bb3-9d67-685d13992528/99902794746.pdf
- https://cdn-cms.f-static.net/uploads/4366385/normal_5f8721d79fdd1.pdf
- https://cdn-cms.f-static.net/uploads/4365635/normal_5f86f75e439ec.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f86fa0a71129.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f86f90e7b908.pdf
- https://cdn.shopify.com/s/files/1/0500/0436/1366/files/encyclopedia_of_religion.pdf
- https://cdn.shopify.com/s/files/1/0430/9650/6521/files/hero_wars_cheats_pc.pdf
- https://cdn.shopify.com/s/files/1/0435/7488/6563/files/economics_rules_book.pdf
- https://cdn.shopify.com/s/files/1/0434/3290/2806/files/14671272868.pdf
- https://cdn.shopify.com/s/files/1/0429/3482/9222/files/73988573386.pdf
- https://site-1043153.mozfiles.com/files/1043153/wimajefojeguvenonorudozi.pdf
- https://site-1039153.mozfiles.com/files/1039153/65583887689.pdf
- https://site-1039156.mozfiles.com/files/1039156/99154183037.pdf
- https://site-1038700.mozfiles.com/files/1038700/44678256202.pdf
- https://site-1043220.mozfiles.com/files/1043220/50311020.pdf
- https://uploads.strikinglycdn.com/files/6ebd0986-1f26-4d80-bcb1-4d681e57e711/vuzududevurarekoze.pdf
- https://uploads.strikinglycdn.com/files/76ce07e7-bef9-4899-9fc6-febd3a771bf6/sajekisekefalisuwi.pdf
- https://uploads.strikinglycdn.com/files/6a5e20e8-8102-455f-891a-677c20f2658b/39226819884.pdf
- https://uploads.strikinglycdn.com/files/2c564fef-7ed8-4e5f-a527-e7aca1317be4/38597322100.pdf
- https://uploads.strikinglycdn.com/files/64244ab2-6076-4dc5-9040-414f6ccdc9e6/9369148320.pdf
- https://uploads.strikinglycdn.com/files/49814139-f931-496a-bc01-b096e8443c2b/siwigixitowojuregid.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1043153.mozfiles.com
- site-1039153.mozfiles.com
- site-1039156.mozfiles.com
- site-1038700.mozfiles.com
- site-1043220.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report