SUSPICIOUS — normal_5f870ebaedddf.pdf
SUSPICIOUS — normal_5f870ebaedddf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ac27f79efb7bb38918d33d046360234e230f98b8e5f2102367408db7730b916b - SHA-1:
1175b430dd39dadc4cd2861a57f11ab55330e632 - MD5:
d63d3ea3e04982c1bf5afd7974d37f72 - ssdeep:
768:ipgGzpDTp0ks4NR8qpi3k0h6J6z3WArLmATUna0K0pRbiqnGeURGUT:JGFfp0g9pak0h46TrL3TUna0K8Rbiqop - TLSH:
T18932AEF35893EC8C77C7AB1399BA10695159D34D6133A7A004883B3ED8BC6BD6E10971 - Submitted as: normal_5f870ebaedddf.pdf
- File type: pdf · Size: 46361 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=android+phone+under+10k+in+bd, https://site-1037069.mozfiles.com/files/1037069/donunale.pdf, https://site-1043760.mozfiles.com/files/1043760/57032262001.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=android+phone+under+10k+in+bd
- https://site-1037069.mozfiles.com/files/1037069/donunale.pdf
- https://site-1043760.mozfiles.com/files/1043760/57032262001.pdf
- https://site-1039608.mozfiles.com/files/1039608/80658943375.pdf
- https://site-1038605.mozfiles.com/files/1038605/89903449874.pdf
- https://uploads.strikinglycdn.com/files/9bed9bcc-b418-43f0-85c5-554b6be831af/zemagebigalef.pdf
- https://uploads.strikinglycdn.com/files/f588db5f-8df7-4d78-8847-7fa66469e5fc/vatofusurekosetejema.pdf
- https://uploads.strikinglycdn.com/files/8fa9ced2-e493-4966-949a-b95ba979dc62/32353389041.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/a8401ec7a9859.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/7922058.pdf
- https://uploads.strikinglycdn.com/files/5c24c778-7062-423b-a881-f68999f29b1d/zijabo.pdf
- https://uploads.strikinglycdn.com/files/551a9c02-5191-426b-afd8-b2cf32929caf/40082486795.pdf
- https://uploads.strikinglycdn.com/files/94cfb012-406a-4d15-b839-7e6c4faff2a8/63464904655.pdf
- https://uploads.strikinglycdn.com/files/ca9f08f7-38d1-40db-9948-2aa616010dab/fuzuniditenivipogez.pdf
- https://uploads.strikinglycdn.com/files/73ee4029-63ca-4fa8-a68c-e9626db4b6fa/dazokovitofufiluwewulanas.pdf
- https://uploads.strikinglycdn.com/files/6fb01216-0476-4700-92d1-295a4ada0b6a/1479394407.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/b628c54eef4e3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1037069.mozfiles.com
- site-1043760.mozfiles.com
- site-1039608.mozfiles.com
- site-1038605.mozfiles.com
- uploads.strikinglycdn.com
- fijojonibiw.weebly.com
- dutitujazekap.weebly.com
- zafozudakajadev.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report