SUSPICIOUS — normal_5f88b3827d162.pdf
SUSPICIOUS — normal_5f88b3827d162.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
735cf4cddcf10799d4a253a54c3b88ae9b6b8d9322e20ebafcd6310ba1da45c7 - SHA-1:
cb74f8e45a6b8b469d44ae6274ea64a60a969e19 - MD5:
1c8bcea93178c77901412ac12ba31ace - ssdeep:
768:itgGzpDkeCr1eCm3nLzsZa5OqMmkueZUD0ln1QJLoblXqMHHON1wE3RR8:ZGFQeCr+XCtVlQLoXHObd3RR8 - TLSH:
T1FB338EF354A7DD4CBA87DB139DEA2569508AD388A132A7A0048C763DD4BC2BD7F10D60 - Submitted as: normal_5f88b3827d162.pdf
- File type: pdf · Size: 51965 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=android+fragment+example+app, https://cdn-cms.f-static.net/uploads/4365601/normal_5f8711b8b03ba.pdf, https://cdn-cms.f-static.net/uploads/4366365/normal_5f870f87b77cc.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=android+fragment+example+app
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f8711b8b03ba.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f870f87b77cc.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f8726c75f5b0.pdf
- https://cdn-cms.f-static.net/uploads/4368741/normal_5f882c6f3b11c.pdf
- https://site-1039500.mozfiles.com/files/1039500/34025309067.pdf
- https://site-1037824.mozfiles.com/files/1037824/38120232473.pdf
- https://site-1039864.mozfiles.com/files/1039864/54796270630.pdf
- https://site-1037205.mozfiles.com/files/1037205/movejanejowasemowuz.pdf
- https://site-1038691.mozfiles.com/files/1038691/32371857831.pdf
- https://uploads.strikinglycdn.com/files/6048994c-67ea-45a5-950d-1024c6f9b3bd/23546383350.pdf
- https://uploads.strikinglycdn.com/files/a727ff21-1842-4c6b-bb9a-d3a8695f7706/wobumofuxebigasirumujotup.pdf
- https://site-1043686.mozfiles.com/files/1043686/jurirazawoniwamo.pdf
- https://site-1042590.mozfiles.com/files/1042590/40593048616.pdf
- https://site-1036691.mozfiles.com/files/1036691/68518888353.pdf
- https://site-1036971.mozfiles.com/files/1036971/55304574714.pdf
- https://site-1038973.mozfiles.com/files/1038973/fupufiponosalex.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/2a5b38eef3430.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/vepulakanug.pdf
- https://nitiruminaxodax.weebly.com/uploads/1/3/0/7/130738633/bezudabani-jasuxavowo.pdf
- https://uploads.strikinglycdn.com/files/f901415c-3a0b-41dd-bf56-6035e840b020/69070883279.pdf
- https://uploads.strikinglycdn.com/files/2250b446-5599-4332-ade5-5f881268115f/47876145942.pdf
- https://uploads.strikinglycdn.com/files/b4997ff1-0f9b-4e3e-ae17-ce1667b95af0/79737513775.pdf
- https://uploads.strikinglycdn.com/files/c043cdcd-cc47-401c-bc53-0d1eaeca4568/voxiniletodasaraxitaka.pdf
- https://uploads.strikinglycdn.com/files/bff64ad9-f56d-4996-9117-57304c7425de/lugewepanufoxubuzinipo.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- site-1039500.mozfiles.com
- site-1037824.mozfiles.com
- site-1039864.mozfiles.com
- site-1037205.mozfiles.com
- site-1038691.mozfiles.com
- uploads.strikinglycdn.com
- site-1043686.mozfiles.com
- site-1042590.mozfiles.com
- site-1036691.mozfiles.com
- site-1036971.mozfiles.com
- site-1038973.mozfiles.com
- guwomenod.weebly.com
- mojivimimujovo.weebly.com
- nitiruminaxodax.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report