SUSPICIOUS — normal_5f8743ce11dae.pdf
SUSPICIOUS — normal_5f8743ce11dae.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8855ebe4914755061551273ef860bd36bb03c688017d582c58bd485db3a98b46 - SHA-1:
fbb1d95d05c773d04ec40cb127b862669353b891 - MD5:
2c0add2ac758f61d5015f93d1f5342e5 - ssdeep:
1536:bGFVpoJL5rXB3FjX2KrwUuJw4fL9T3P/BQna:6FVpoJL/p2K0bw+ZN - TLSH:
T14933ADF71597ED8D7B87AB13AEE620181498C7CA6133A660489C373CC5BC7BD6E01912 - Submitted as: normal_5f8743ce11dae.pdf
- File type: pdf · Size: 51989 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=guided+sleep+meditation+for+healing, https://uploads.strikinglycdn.com/files/68083103-e833-48bd-88cc-37b6e52da998/12269154428.pdf, https://uploads.strikinglycdn.com/files/274b639b-b47c-42f1-b871-c4e899abc146/nuzisanerako.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=guided+sleep+meditation+for+healing
- https://uploads.strikinglycdn.com/files/68083103-e833-48bd-88cc-37b6e52da998/12269154428.pdf
- https://uploads.strikinglycdn.com/files/274b639b-b47c-42f1-b871-c4e899abc146/nuzisanerako.pdf
- https://uploads.strikinglycdn.com/files/6ad3a7d5-42c2-4ebb-b37b-9d47292e82b4/78304633318.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/divili_dapixi.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/a6ecbf06788df.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/9985793.pdf
- https://cdn.shopify.com/s/files/1/0437/7152/7319/files/67418090188.pdf
- https://cdn.shopify.com/s/files/1/0495/8794/5622/files/baguwirodojofox.pdf
- https://site-1038423.mozfiles.com/files/1038423/sowiwemonokugabadefovisa.pdf
- https://site-1040896.mozfiles.com/files/1040896/50847217472.pdf
- https://site-1040373.mozfiles.com/files/1040373/lupowowejimofufosexekolus.pdf
- https://site-1041489.mozfiles.com/files/1041489/lajerigesiker.pdf
- https://cdn.shopify.com/s/files/1/0482/9931/1268/files/chicago_typewriter_guney_kore_sinemasi.pdf
- https://cdn.shopify.com/s/files/1/0486/2076/5344/files/xavavinurixuxagijisetan.pdf
- https://cdn.shopify.com/s/files/1/0434/9729/1941/files/descargar_ciudades_de_papel_para_celular.pdf
- https://cdn.shopify.com/s/files/1/0499/9538/2939/files/3d_photo_maker_android.pdf
- https://cdn.shopify.com/s/files/1/0430/5843/0106/files/lomilis.pdf
- https://cdn.shopify.com/s/files/1/0484/3746/1160/files/3052705895.pdf
- https://cdn.shopify.com/s/files/1/0480/9103/7859/files/83949984557.pdf
- https://cdn.shopify.com/s/files/1/0437/0874/3835/files/forgotten_realms_campaign_setting_3.5.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- jakedekokobara.weebly.com
- mupibidegupek.weebly.com
- tipefejiri.weebly.com
- cdn.shopify.com
- site-1038423.mozfiles.com
- site-1040896.mozfiles.com
- site-1040373.mozfiles.com
- site-1041489.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report