SUSPICIOUS — normal_5f8905023c034.pdf
SUSPICIOUS — normal_5f8905023c034.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
bb467bfe4d403c2bd3d3fd0099e0df04b85b6e0788374c94cdd73c8758340a45 - SHA-1:
799c3244f2aeedabb3e94f3959a2d63a8a587751 - MD5:
ccd5f3abb2b8547a52a39d16ab940581 - ssdeep:
768:igGzpDIpMmRYbNou3w/YocEMCIvamDnpm8lYCfAN3GFwsWXGjqq2VQtUrMmPlREE:/GFMpMD4DKnpxnfAKj3iQyrMQREasWl - TLSH:
T121338EF310E3DC4C7E8B9B03ADA715A9708AC6896123D7E0548C762DC4BCAED2F00965 - Submitted as: normal_5f8905023c034.pdf
- File type: pdf · Size: 49456 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=google+play+store+amazon+fire+tablet+apk, https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/3121684.pdf, https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/da0366c694e301c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=google+play+store+amazon+fire+tablet+apk
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/3121684.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/da0366c694e301c.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/wudipikex.pdf
- https://cdn-cms.f-static.net/uploads/4367305/normal_5f8764f4e5aca.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f873d196d3e9.pdf
- https://cdn-cms.f-static.net/uploads/4370263/normal_5f8904696a4df.pdf
- https://cdn-cms.f-static.net/uploads/4368956/normal_5f87a042dabaf.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f88c21414fff.pdf
- https://uploads.strikinglycdn.com/files/8fdee722-e48c-47ef-a3a8-330ab6da3931/jobaxexe.pdf
- https://uploads.strikinglycdn.com/files/abc2f8f4-2dd8-443b-b4fa-d3765065bbe9/26659895878.pdf
- https://uploads.strikinglycdn.com/files/b10e69fc-9713-4819-9d55-25fbcc3369e8/voxupel.pdf
- https://uploads.strikinglycdn.com/files/615c563f-9eb2-4b99-9ee8-32d7dde5cabe/63297542803.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f88c639c4fc5.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f879a8a70577.pdf
- https://cdn-cms.f-static.net/uploads/4365552/normal_5f88c3a777d5b.pdf
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f876219b20d9.pdf
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f87428503f79.pdf
- https://cdn-cms.f-static.net/uploads/4367952/normal_5f879ca355a06.pdf
- https://cdn-cms.f-static.net/uploads/4369659/normal_5f88d2eb15e0d.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f8749a7cb032.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- 5.br
- kelobutino.weebly.com
- sesuwulot.weebly.com
- povutepumik.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report