SUSPICIOUS — normal_5f87590993b9b.pdf
SUSPICIOUS — normal_5f87590993b9b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
892b8b506c9a5d009e953c5a4eba3e288157c596a3a1429a8c7fc2df0b514c40 - SHA-1:
b93b53290e33483532af1840e20c215c7787ed96 - MD5:
07706801868c22a6de2951fa28afe98b - ssdeep:
1536:eGFqp8htlyrjHJEvoG4ggAOcJAb4KOgJdkhA0:HFqp2CXHJi+gecJG4KOgJWx - TLSH:
T1BC34B0F390C7ED8D7AC5AB43ACA610957099D7883272EAA014D8772DD4BC6FCBE10560 - Submitted as: normal_5f87590993b9b.pdf
- File type: pdf · Size: 52677 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=different+types+of+chromatography+techniques+pdf, https://uploads.strikinglycdn.com/files/b960cd2d-0d10-4dfd-b7f6-514ae48c9f29/85707547861.pdf, https://uploads.strikinglycdn.com/files/2ae93aa5-dc54-4bb8-a31c-0a56bcf1eb45/luteduwasuf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=different+types+of+chromatography+techniques+pdf
- https://uploads.strikinglycdn.com/files/b960cd2d-0d10-4dfd-b7f6-514ae48c9f29/85707547861.pdf
- https://uploads.strikinglycdn.com/files/2ae93aa5-dc54-4bb8-a31c-0a56bcf1eb45/luteduwasuf.pdf
- https://uploads.strikinglycdn.com/files/f444cae9-d2a6-4d3e-b3e8-b22403e18684/16940457987.pdf
- https://buluzuzumaz.weebly.com/uploads/1/3/1/6/131636727/1692507.pdf
- https://site-1048253.mozfiles.com/files/1048253/zudukiwulegepozosovemulir.pdf
- https://site-1039797.mozfiles.com/files/1039797/lapefupikanevofubawovebal.pdf
- https://site-1038820.mozfiles.com/files/1038820/18696781135.pdf
- https://cdn.shopify.com/s/files/1/0498/1250/4731/files/tos_sorcerer_guide.pdf
- https://cdn.shopify.com/s/files/1/0504/2795/3312/files/clean_room_design_guidelines.pdf
- https://cdn.shopify.com/s/files/1/0437/1188/9573/files/85872336752.pdf
- https://cdn.shopify.com/s/files/1/0437/4514/9079/files/firigizipepefamali.pdf
- https://uploads.strikinglycdn.com/files/8252e871-d673-4b49-b1b0-6f52c7e93a69/xodawixid.pdf
- https://uploads.strikinglycdn.com/files/f660c484-ec90-498f-9d74-84ff99a9a819/tivipipedasibonarowuvijok.pdf
- https://uploads.strikinglycdn.com/files/57fb4b22-09b8-4bd3-b21e-0d3a155239b7/15517873498.pdf
- https://uploads.strikinglycdn.com/files/2771743d-a31b-40f5-8922-b8314f841d73/duwipa.pdf
- https://cdn.shopify.com/s/files/1/0440/1620/5989/files/happy_wheels_totaljerkface_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0503/8873/0054/files/clothes_in_english_worksheet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- buluzuzumaz.weebly.com
- site-1048253.mozfiles.com
- site-1039797.mozfiles.com
- site-1038820.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report