SUSPICIOUS — normal_5f88c6ae2be37.pdf
SUSPICIOUS — normal_5f88c6ae2be37.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
89923ab7f8e6f34e1a68b397b152be4b8d829bb82dac461c8c68b3322e7c22f0 - SHA-1:
ad720f88be2ea633223277b193374cb708732c3e - MD5:
56563426877c7169ac67b58c785d144c - ssdeep:
768:29gGzpDSpeJ0kHCI077Q/l2Sqbt/beOzZOhMChpCmr5c1FgxvWrm:JGFmpen21/beOzkh1hpC4i4urm - TLSH:
T10B317CF311A3ED8C7A8B6F439EAB019D644592897173A6A014D8336CD4BC6FD7F00661 - Submitted as: normal_5f88c6ae2be37.pdf
- File type: pdf · Size: 40084 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=english+tenses+test+intermediate+pdf, https://cdn.shopify.com/s/files/1/0437/7680/2967/files/felewaveriwididabegitoxof.pdf, https://cdn.shopify.com/s/files/1/0479/3696/2716/files/lord_henry_wotton_character_traits.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=english+tenses+test+intermediate+pdf
- https://cdn.shopify.com/s/files/1/0437/7680/2967/files/felewaveriwididabegitoxof.pdf
- https://cdn.shopify.com/s/files/1/0479/3696/2716/files/lord_henry_wotton_character_traits.pdf
- https://cdn.shopify.com/s/files/1/0440/6480/0918/files/dye_i4_mask_black_gold.pdf
- https://site-1041766.mozfiles.com/files/1041766/53033148003.pdf
- https://site-1038602.mozfiles.com/files/1038602/zaneruj.pdf
- https://site-1036665.mozfiles.com/files/1036665/70119033529.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/739bdf.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/bibesekukemugedovofa.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/5238855.pdf
- https://cdn.shopify.com/s/files/1/0484/0679/0296/files/tantra_georg_feuerstein.pdf
- https://cdn.shopify.com/s/files/1/0476/9329/9878/files/introduction_to_scripting_in_python_specialization_github.pdf
- https://cdn.shopify.com/s/files/1/0429/3243/7151/files/buvilitetodu.pdf
- https://cdn.shopify.com/s/files/1/0481/1879/2345/files/electron_arrangement_review_worksheet.pdf
- https://site-1040284.mozfiles.com/files/1040284/73392160757.pdf
- https://site-1043798.mozfiles.com/files/1043798/lifotilimubutetajubumusov.pdf
- https://site-1048491.mozfiles.com/files/1048491/saxupej.pdf
- https://site-1039639.mozfiles.com/files/1039639/pufunuzukuzuvakibuvomodo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1041766.mozfiles.com
- site-1038602.mozfiles.com
- site-1036665.mozfiles.com
- wepugimi.weebly.com
- jemiwuwavaza.weebly.com
- nudojafobedem.weebly.com
- site-1040284.mozfiles.com
- site-1043798.mozfiles.com
- site-1048491.mozfiles.com
- site-1039639.mozfiles.com
- w.se
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report