SUSPICIOUS — normal_5f88a8c02d0ae.pdf
SUSPICIOUS — normal_5f88a8c02d0ae.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
9e76ed2ffabb5e32d3163e9b8f167df140c5b4cb5a66eb134c4768c63113b01b - SHA-1:
9bb22df9971eb28400f1d4e94a610fb413f1ec1a - MD5:
2af4c5f54d3f7b36bad1e75d6b0ac4c7 - ssdeep:
768:ygGzpDqp7ZoohLwUT7NjGsB7ZQ2ZtjSvUwReU5Iy3Cjn19sdVkboQwQoo7jmuz:vGF+p7mVcy55j3C0dVkboQ/Zjmuz - TLSH:
T113306BF350A7DE8D3A87AB83ACF715A95449C78C7136A760448C6B2CC5BC6ACBF00560 - Submitted as: normal_5f88a8c02d0ae.pdf
- File type: pdf · Size: 38210 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=introduccion+a+la+psicologia+social+iba%25C3%25B1ez+pdf, https://cdn-cms.f-static.net/uploads/4369626/normal_5f885808872ee.pdf, https://cdn-cms.f-static.net/uploads/4366964/normal_5f8745397464e.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=introduccion+a+la+psicologia+social+iba%25C3%25B1ez+pdf
- https://cdn-cms.f-static.net/uploads/4369626/normal_5f885808872ee.pdf
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f8745397464e.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f87e41355344.pdf
- https://cdn-cms.f-static.net/uploads/4366015/normal_5f875949d16cf.pdf
- https://cdn-cms.f-static.net/uploads/4366628/normal_5f8737e2191be.pdf
- https://cdn.shopify.com/s/files/1/0431/9055/0679/files/bill_burr_im_sorry_you_feel_that_way_black_and_white.pdf
- https://cdn.shopify.com/s/files/1/0440/3062/3894/files/pelev.pdf
- https://cdn.shopify.com/s/files/1/0484/3746/1160/files/bubble_witch_saga_3_apk.pdf
- https://cdn.shopify.com/s/files/1/0500/3296/7830/files/pihu_myra_vishwakarma_real_age.pdf
- https://cdn.shopify.com/s/files/1/0483/8965/2648/files/new_world_record_flathead_catfish.pdf
- https://cdn.shopify.com/s/files/1/0483/7838/0441/files/machine_drawing_assembly.pdf
- https://cdn.shopify.com/s/files/1/0430/6042/8962/files/bosch_4000_table_saw_review.pdf
- https://cdn.shopify.com/s/files/1/0434/0957/1989/files/10309861150.pdf
- https://cdn.shopify.com/s/files/1/0431/2304/8610/files/google_drive_trolls_full_movie.pdf
- https://site-1039235.mozfiles.com/files/1039235/gokabezevudedusuguxewagaw.pdf
- https://site-1043258.mozfiles.com/files/1043258/81016784127.pdf
- https://uploads.strikinglycdn.com/files/fd47baa1-822f-4791-a947-8aeb13f1974f/vesumefomenamikuvitojef.pdf
- https://uploads.strikinglycdn.com/files/e8b3b90d-c241-4634-ba30-9803b141b592/jiwukuzasakekelimuzam.pdf
- https://uploads.strikinglycdn.com/files/32a8969f-5ead-49db-9954-d5fae6804e3d/sewiri.pdf
- https://uploads.strikinglycdn.com/files/9a4bed61-fb7b-4ad0-ba5f-af8a5210f1fc/xilofimufamawolowebeve.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1039235.mozfiles.com
- site-1043258.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report