SUSPICIOUS — normal_5f8737d3f191e.pdf
SUSPICIOUS — normal_5f8737d3f191e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
84c51a628af0d8c5b019cf21378741fe5dc80a0e4bae91e1305405101bf5c762 - SHA-1:
793296912feb2350dc431b3ba546e5f72b3709a9 - MD5:
4f043c823a7492ab423b977c7bbf6b9a - ssdeep:
768:jIgGzpDDpxJfNlnZllbHl54IzmiYk+bCA66SkUMyhNqkfeGJsjbMQB0pv3dH:RGFnpoOA6660kfeGJs8tZ3dH - TLSH:
T147327DF35497ED4C7A47DB17A9EB2A591049C38D6222E35014CC6B3DC4BC6BD7E10860 - Submitted as: normal_5f8737d3f191e.pdf
- File type: pdf · Size: 43419 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=download+easeus+mobisaver+for+android, https://cdn.shopify.com/s/files/1/0437/0887/4906/files/slimans_used_cars.pdf, https://cdn.shopify.com/s/files/1/0432/2911/8627/files/subamolagedi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=download+easeus+mobisaver+for+android
- https://cdn.shopify.com/s/files/1/0437/0887/4906/files/slimans_used_cars.pdf
- https://cdn.shopify.com/s/files/1/0432/2911/8627/files/subamolagedi.pdf
- https://cdn.shopify.com/s/files/1/0499/3561/4120/files/jezawon.pdf
- https://cdn.shopify.com/s/files/1/0481/3301/3655/files/masij.pdf
- https://cdn.shopify.com/s/files/1/0496/3926/0309/files/area_code_85203.pdf
- https://uploads.strikinglycdn.com/files/313659d1-f385-47ad-8b5e-9f3d1881b85c/41500914520.pdf
- https://uploads.strikinglycdn.com/files/d3fe49d1-4acf-4e75-98de-b1a339efaca1/vawubeb.pdf
- https://uploads.strikinglycdn.com/files/e6c893a4-d2fb-434d-a7da-fa96499ef8f2/14246272597.pdf
- https://uploads.strikinglycdn.com/files/0574ab34-f1d2-4e26-940e-f1ec54eb2afd/3757365407.pdf
- https://uploads.strikinglycdn.com/files/6c90bbcc-28bf-4742-a5f9-72d8a5e3b271/8826168434.pdf
- https://cdn.shopify.com/s/files/1/0428/9455/7350/files/zombie_cafe_apk_2020.pdf
- https://cdn.shopify.com/s/files/1/0480/8612/2660/files/township_game_tips_2018.pdf
- https://cdn.shopify.com/s/files/1/0483/5731/0615/files/remove_avast_browser_update.pdf
- https://cdn.shopify.com/s/files/1/0502/8410/1804/files/candy_crush_2020_download_apk.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f8704dbe3e1d.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8732f8d9135.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f8716b78cf51.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f86fbecea432.pdf
- https://uploads.strikinglycdn.com/files/bc861fc2-28ee-4548-8a73-d57e25328aac/tonidubosofasilevomofafu.pdf
- https://uploads.strikinglycdn.com/files/4954175a-2f0d-4448-97f2-68970b21f74f/fupibutovuzugoperelek.pdf
- https://uploads.strikinglycdn.com/files/4b73aafc-1057-4089-a3d4-42e38f9f71dc/50530064146.pdf
- https://site-1039535.mozfiles.com/files/1039535/81488518261.pdf
- https://site-1042282.mozfiles.com/files/1042282/rinivokezisexubukow.pdf
- https://site-1048531.mozfiles.com/files/1048531/rokegog.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1039535.mozfiles.com
- site-1042282.mozfiles.com
- site-1048531.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report