SUSPICIOUS — normal_5f87030a72d4b.pdf
SUSPICIOUS — normal_5f87030a72d4b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a2aafc4ffb5b988b7116bf5dee88696b01b5f33a32b6c6c307fab495126432ab - SHA-1:
13d1ec5a45bddfda771262f4ab93304ffecf56ed - MD5:
ee65ac88d059ba9f2b2c8595d625779f - ssdeep:
768:RNgGzpDrpJWFw6n0iwd7mm9W/WmOpX/mapHUFmn6ma0rFI8QqI/V7VK:EGFHpzgFm6L0GtqI/V7VK - TLSH:
T1FF328EF31067ED4C3A8B6F03ADAB1A9EA185C789603393905488766CD4BC9FD7F10960 - Submitted as: normal_5f87030a72d4b.pdf
- File type: pdf · Size: 44966 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=copyright+symbol+whatsapp+android, https://cdn.shopify.com/s/files/1/0266/7777/2457/files/spanish_words_in_alphabetical_order_list.pdf, https://cdn.shopify.com/s/files/1/0431/4975/4519/files/50269616456.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=copyright+symbol+whatsapp+android
- https://cdn.shopify.com/s/files/1/0266/7777/2457/files/spanish_words_in_alphabetical_order_list.pdf
- https://cdn.shopify.com/s/files/1/0431/4975/4519/files/50269616456.pdf
- https://cdn.shopify.com/s/files/1/0495/6182/9528/files/18965284944.pdf
- https://site-1040561.mozfiles.com/files/1040561/wadifozezapijezagil.pdf
- https://site-1039351.mozfiles.com/files/1039351/vusini.pdf
- https://site-1039837.mozfiles.com/files/1039837/siwotoboxuvunowovoxe.pdf
- https://site-1042510.mozfiles.com/files/1042510/zexonuxojapelad.pdf
- https://cdn.shopify.com/s/files/1/0434/1415/9521/files/genukototikakovakotimot.pdf
- https://cdn.shopify.com/s/files/1/0482/5202/7041/files/nilunute.pdf
- https://cdn.shopify.com/s/files/1/0428/6650/7942/files/i_read_the_incredible_journey_by_sheila_burnford.pdf
- https://cdn.shopify.com/s/files/1/0434/9542/4165/files/fifuzurixifu.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/winepogor.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/a8401ec7a9859.pdf
- https://uploads.strikinglycdn.com/files/29edf6c4-a3c9-45bb-a9af-dc5f325b7277/vazopaduretabupexijofu.pdf
- https://uploads.strikinglycdn.com/files/cf036b28-447c-4dfe-bdef-a5e14d27c7c0/mozegikerijutarikedibep.pdf
- https://uploads.strikinglycdn.com/files/28ab4272-d24d-44e0-925a-ee8789d22095/sotevufo.pdf
- https://uploads.strikinglycdn.com/files/3367cee2-1bd5-4e98-8674-9d6d427da52a/11415652680.pdf
- https://uploads.strikinglycdn.com/files/ffea1ec1-8897-4723-8ce8-d5236eea82ef/jijagivekofu.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f86f464641b1.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f8702ec2e1ff.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f86fbd91b5ce.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f86ff84e90cf.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f8700deb12c1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1040561.mozfiles.com
- site-1039351.mozfiles.com
- site-1039837.mozfiles.com
- site-1042510.mozfiles.com
- zoxuzuxebexot.weebly.com
- fijojonibiw.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report