SUSPICIOUS — normal_5f871cf1be6ac.pdf
SUSPICIOUS — normal_5f871cf1be6ac.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
bf30359eee78a7c8380c0b68729ed517a5e80271a1e3f4494fed8f447c8043d6 - SHA-1:
d37b59e5183913ed2e21f39dfd7c19225160ba42 - MD5:
4915e5b5e8587171287650c1529370fe - ssdeep:
768:3MgGzpDdpbc1+/VXfN0NJLdfcN21ZEMXtZUnur5mxDfgP2BNOj00gRSb/YAyI6j7:5GFRpoZF0FflaIJQb/YAwbyX3+R - TLSH:
T133338EF3609BED4C768B9713ADAB1566A489C38CE136D790448C762CD5BC2BD7E11820 - Submitted as: normal_5f871cf1be6ac.pdf
- File type: pdf · Size: 49639 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=mobogenie+market+app+download+for+android, https://cdn-cms.f-static.net/uploads/4365598/normal_5f870ee04e9ee.pdf, https://cdn-cms.f-static.net/uploads/4366063/normal_5f87014978ecb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=mobogenie+market+app+download+for+android
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f870ee04e9ee.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f87014978ecb.pdf
- https://cdn-cms.f-static.net/uploads/4366351/normal_5f870f66c0cf1.pdf
- https://cdn-cms.f-static.net/uploads/4366042/normal_5f87000c2d681.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f870ce9e101d.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8719c96936e.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f870132d11c6.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f870917efa9a.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f870f36b8848.pdf
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/tufifejus_juwugotelakug_jemibil.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf
- https://jovofodofipepij.weebly.com/uploads/1/3/2/6/132682866/5728316.pdf
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/a307e022daaf0e8.pdf
- https://pivozedotafi.weebly.com/uploads/1/3/1/0/131070355/felizoromubipiworu.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/jelegojisulone.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/4ea5f8282d36a85.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/6431815.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/foburadip.pdf
- https://cdn.shopify.com/s/files/1/0499/3295/9912/files/6455170805.pdf
- https://cdn.shopify.com/s/files/1/0498/3717/9042/files/simcity_buildit_hack_no_human_verification.pdf
- https://cdn.shopify.com/s/files/1/0483/9548/5352/files/la_gran_tribulacion_pelicula.pdf
- https://cdn.shopify.com/s/files/1/0434/3005/2005/files/32398717991.pdf
- https://cdn.shopify.com/s/files/1/0498/8161/2446/files/53651795840.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/jerugoka_javun_ronulavotijogif.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- tajurasexir.weebly.com
- jatorogerujew.weebly.com
- jovofodofipepij.weebly.com
- pivozedotafi.weebly.com
- mojivimimujovo.weebly.com
- vuzevarezevarot.weebly.com
- jakedekokobara.weebly.com
- xojerajap.weebly.com
- cdn.shopify.com
- jawowigo.weebly.com
- jawasolasazilem.weebly.com
- dimaxafazeza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report