SUSPICIOUS — normal_5f88a322dd528.pdf
SUSPICIOUS — normal_5f88a322dd528.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
74843218ee66b2859eec68b171d4fc6e7e487c6b8c8de8161ab1964792a4993d - SHA-1:
1e4fc45a7829838042ff045827b230a1a6ba385d - MD5:
d5638243227df15c1206b2a1a4308bdc - ssdeep:
768:4gGzpDLeZvFmz4FIM3MpJ/vVi9Ujskga1cmis48DtW7l45yGCGF:VGFXeZoVi6jsA1cmis48Do7l4dCGF - TLSH:
T163326CF310A7ED8C7A8F9F839DEB019D504AD789312297904588762DD47C6EE7F10A60 - Submitted as: normal_5f88a322dd528.pdf
- File type: pdf · Size: 47416 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=%25C4%258Derven%25C3%25BD+trpasl%25C3%25ADk+kniha+pdf, https://uploads.strikinglycdn.com/files/810fd27e-4505-41ef-ab4a-7254a17df890/tutuj.pdf, https://uploads.strikinglycdn.com/files/f9aa8631-4017-4e5a-8c8e-35d9ee25b93b/vobijibixoma.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=%25C4%258Derven%25C3%25BD+trpasl%25C3%25ADk+kniha+pdf
- https://uploads.strikinglycdn.com/files/810fd27e-4505-41ef-ab4a-7254a17df890/tutuj.pdf
- https://uploads.strikinglycdn.com/files/f9aa8631-4017-4e5a-8c8e-35d9ee25b93b/vobijibixoma.pdf
- https://uploads.strikinglycdn.com/files/cc5597a3-1a40-43d7-9246-7de006794909/55855623170.pdf
- https://uploads.strikinglycdn.com/files/331d47bb-5869-4c1e-b318-d6ffd5f7f207/3280447398.pdf
- https://uploads.strikinglycdn.com/files/b903006e-9733-4f3b-abf5-780030ba7665/87415489491.pdf
- https://uploads.strikinglycdn.com/files/84a6a328-9490-465b-85f1-4733fcf7327c/39332020279.pdf
- https://uploads.strikinglycdn.com/files/b2d475e1-f2fc-44e3-b588-ab00c0dba797/wamutukafiwexiliw.pdf
- https://uploads.strikinglycdn.com/files/c994bdaa-eca4-4a5a-9bab-8da80d43d940/56757119455.pdf
- https://site-1040209.mozfiles.com/files/1040209/guzapodagesugosadet.pdf
- https://site-1042100.mozfiles.com/files/1042100/91268337811.pdf
- https://site-1039624.mozfiles.com/files/1039624/download_pes_17_apkobb_offline.pdf
- https://cdn.shopify.com/s/files/1/0438/4522/2557/files/r.m._drake_beautiful_chaos.pdf
- https://cdn.shopify.com/s/files/1/0266/9042/0924/files/comprehensive_peace_agreement_nepal.pdf
- https://cdn.shopify.com/s/files/1/0436/1220/9309/files/kite_runner_important_characters.pdf
- https://cdn.shopify.com/s/files/1/0435/4506/7684/files/google_teacher_certification_practice_test.pdf
- https://site-1038586.mozfiles.com/files/1038586/vuvewapidewulo.pdf
- https://site-1041598.mozfiles.com/files/1041598/45460725113.pdf
- https://site-1040432.mozfiles.com/files/1040432/mumomipibezoxuset.pdf
- https://site-1037260.mozfiles.com/files/1037260/nopulutunasososudidonibi.pdf
- https://site-1048568.mozfiles.com/files/1048568/22405119785.pdf
- https://site-1038526.mozfiles.com/files/1038526/xakogukojedibezekavuzada.pdf
- https://site-1039413.mozfiles.com/files/1039413/minomomerarotanipavug.pdf
- https://site-1043328.mozfiles.com/files/1043328/rabijupabug.pdf
- https://site-1038707.mozfiles.com/files/1038707/55154170483.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1040209.mozfiles.com
- site-1042100.mozfiles.com
- site-1039624.mozfiles.com
- cdn.shopify.com
- site-1038586.mozfiles.com
- site-1041598.mozfiles.com
- site-1040432.mozfiles.com
- site-1037260.mozfiles.com
- site-1048568.mozfiles.com
- site-1038526.mozfiles.com
- site-1039413.mozfiles.com
- site-1043328.mozfiles.com
- site-1038707.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report