SUSPICIOUS — normal_5f8a1bd8cf154.pdf
SUSPICIOUS — normal_5f8a1bd8cf154.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
860b3cddbfa0ac2feda561eb75e5fe4b0d1c72f2a82736d5e8fb7fbbda77e9ac - SHA-1:
0a7aa66873cdade27f787de0eacc788c6af986bd - MD5:
d40bb164012f13e90d700a6054a033eb - ssdeep:
768:WgGzpDupB6COJgaOe5dVwv3w7VJY6+2norkOCc8dT9zmX9B7GamCA3Idkdr8yKY8:DGF6pfYY6+2nY8c8dxiX7VmCA4dkJ9dO - TLSH:
T1C4328CF70097ED8C3A879B03AEAB156C944DD7886072D66458CC762CC0BC7BE3E51A61 - Submitted as: normal_5f8a1bd8cf154.pdf
- File type: pdf · Size: 44936 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=callippe+golf+course+guide, https://uploads.strikinglycdn.com/files/6922122a-b1e4-481c-9e45-258e74e5bb9b/30963930818.pdf, https://uploads.strikinglycdn.com/files/9001260d-b805-4d22-ac43-6ba28ff0bef5/viweviwokavuxa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=callippe+golf+course+guide
- https://uploads.strikinglycdn.com/files/6922122a-b1e4-481c-9e45-258e74e5bb9b/30963930818.pdf
- https://uploads.strikinglycdn.com/files/9001260d-b805-4d22-ac43-6ba28ff0bef5/viweviwokavuxa.pdf
- https://uploads.strikinglycdn.com/files/264f9993-b5b3-4363-9424-8f174276499d/31338279629.pdf
- https://uploads.strikinglycdn.com/files/545cdc8c-77e8-49ee-adb8-65ae5365b39d/57053406788.pdf
- https://uploads.strikinglycdn.com/files/d2c40a57-482f-4ed2-9877-0f352a4a97f2/20264460359.pdf
- https://uploads.strikinglycdn.com/files/bdb58e1b-bbe2-482c-b0c1-5098735fc29e/26258921507.pdf
- https://uploads.strikinglycdn.com/files/84cf6232-6681-4788-8c14-71a62e920629/50_sombras_mas_oscuras_pelicula_completa_repelis.pdf
- https://uploads.strikinglycdn.com/files/a232aea7-ba86-4488-83d1-47f18aebb8ba/lapuzuka.pdf
- https://uploads.strikinglycdn.com/files/556ec72b-a702-4f85-85e7-da0463612f60/xalojulanugi.pdf
- https://uploads.strikinglycdn.com/files/c301e5c8-3e11-46f2-9e03-6388c355568a/misugop.pdf
- https://gadigode.weebly.com/uploads/1/3/2/6/132680949/b11611edfca2510.pdf
- https://xijonezamo.weebly.com/uploads/1/3/1/4/131407630/59074.pdf
- https://bibeliki.weebly.com/uploads/1/3/0/7/130738572/7530641.pdf
- https://sisaseno.weebly.com/uploads/1/3/0/7/130776680/bojaseweku-dawanili-demaronesapoja-defokutuzigezo.pdf
- https://welavofewefose.weebly.com/uploads/1/3/0/8/130813025/79c052.pdf
- https://cdn.shopify.com/s/files/1/0429/3486/1991/files/descargar_como_ser_un_latin_lover_por_utorrent.pdf
- https://cdn.shopify.com/s/files/1/0433/8787/9587/files/the_intelligencer_and_wheeling_news_register.pdf
- https://cdn.shopify.com/s/files/1/0500/2743/0059/files/63501864861.pdf
- https://cdn.shopify.com/s/files/1/0465/1014/5694/files/sense_and_sensibility_sparknotes_quiz.pdf
- https://cdn.shopify.com/s/files/1/0483/9908/9824/files/wagakuliwulo.pdf
- https://cdn-cms.f-static.net/uploads/4373509/normal_5f89d7bfe9702.pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f8a117616bf6.pdf
- https://cdn-cms.f-static.net/uploads/4366623/normal_5f87834496f45.pdf
- https://cdn-cms.f-static.net/uploads/4375350/normal_5f8a16fd29bf6.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- gadigode.weebly.com
- xijonezamo.weebly.com
- bibeliki.weebly.com
- sisaseno.weebly.com
- welavofewefose.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report