SUSPICIOUS — normal_5f87af559efb9.pdf
SUSPICIOUS — normal_5f87af559efb9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
72789626d65378e38c776ddcaf813e68660d3e6e6cb26515f628a55e7db572be - SHA-1:
372a4147717a145318cd768fa119b6aa97b06b2e - MD5:
d6331f0cdd53e533e670d4cd03413576 - ssdeep:
768:7UgGzpDvDpHzZH6/+Fv3EYpC8u8Q3grc4cdWX2AWoI6ZkTYzLQE1hL2nZU8:VGF7DpHzdS+FfEjIFXviYXQE1hynZU8 - TLSH:
T161339EF350B7EC4C7BCB67439DAA06A9518AC78DA022D79044C8672DC0BCAFD7E00A55 - Submitted as: normal_5f87af559efb9.pdf
- File type: pdf · Size: 48174 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=enable+developer+options+chrome+android, https://uploads.strikinglycdn.com/files/75e72dff-3fc4-4b69-9806-3f70b29d85ef/85894005805.pdf, https://uploads.strikinglycdn.com/files/39696a9a-70af-4813-a02b-8c3ecbb3ad5d/kiguk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=enable+developer+options+chrome+android
- https://uploads.strikinglycdn.com/files/75e72dff-3fc4-4b69-9806-3f70b29d85ef/85894005805.pdf
- https://uploads.strikinglycdn.com/files/39696a9a-70af-4813-a02b-8c3ecbb3ad5d/kiguk.pdf
- https://uploads.strikinglycdn.com/files/1080613d-3846-4849-8766-cb0e0358d263/kanudanarasekuj.pdf
- https://uploads.strikinglycdn.com/files/9d11c353-779b-48d8-8a65-e5c047f8ec84/delitowajusotufigobop.pdf
- https://uploads.strikinglycdn.com/files/7f2b2f7d-173e-4353-95b4-2b04aaef0a55/jazeninapidovojufusefo.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8778614ba42.pdf
- https://cdn-cms.f-static.net/uploads/4366366/normal_5f877c893a07d.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f8716e6555a3.pdf
- https://site-1038904.mozfiles.com/files/1038904/12163756383.pdf
- https://site-1040132.mozfiles.com/files/1040132/67990272694.pdf
- https://site-1040179.mozfiles.com/files/1040179/gojunexizifiniwoge.pdf
- https://uploads.strikinglycdn.com/files/e5aa9f66-9f5a-41b7-8e7e-1fb803350e75/40349195855.pdf
- https://uploads.strikinglycdn.com/files/af009cb5-2564-47dd-a65c-835bf4c9d803/51140920400.pdf
- https://uploads.strikinglycdn.com/files/2bb673e2-19bc-47e2-bd6e-d9c2c7428ce5/88347938679.pdf
- https://uploads.strikinglycdn.com/files/667f832c-e219-4834-9328-b0aaea3b8070/suzabalumibatokenupivoko.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/wuxuvadure-fanate.pdf
- https://punadojum.weebly.com/uploads/1/3/2/6/132680976/xuxaposofa.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/jefifuxewa.pdf
- https://site-1044019.mozfiles.com/files/1044019/keguxuxemobid.pdf
- https://site-1040145.mozfiles.com/files/1040145/20358909971.pdf
- https://site-1039749.mozfiles.com/files/1039749/95552983554.pdf
- https://site-1041864.mozfiles.com/files/1041864/15280364082.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1038904.mozfiles.com
- site-1040132.mozfiles.com
- site-1040179.mozfiles.com
- sepikupi.weebly.com
- punadojum.weebly.com
- jufaxexave.weebly.com
- site-1044019.mozfiles.com
- site-1040145.mozfiles.com
- site-1039749.mozfiles.com
- site-1041864.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report