SUSPICIOUS — normal_5f89620ce2955.pdf
SUSPICIOUS — normal_5f89620ce2955.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
bfdeec8f471762850198f35f572c649c5fa92e67d0930ea6f0633278c673ecae - SHA-1:
db2e393494c2dc39bee82c0e08e68a13817a18ad - MD5:
ec3ea147666f53f4a0a0134deb90943c - ssdeep:
1536:YqGFbpbSplGOnDVtoIWz0aPYGvSGZ2dPb:YTFbpbSpbnDrS0agGvzst - TLSH:
T1A3348DF36893ED8C79C6DB4368A619592189C78C7237D76048DC7B2DD4BCAAD6F10820 - Submitted as: normal_5f89620ce2955.pdf
- File type: pdf · Size: 56172 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=haryana+government+calendar+2020+pdf, https://cdn.shopify.com/s/files/1/0440/6929/0149/files/atec_pitching_machine_wheels_melting.pdf, https://cdn.shopify.com/s/files/1/0430/4237/3785/files/how_to_install_apk_on_windows_phone.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=haryana+government+calendar+2020+pdf
- https://cdn.shopify.com/s/files/1/0440/6929/0149/files/atec_pitching_machine_wheels_melting.pdf
- https://cdn.shopify.com/s/files/1/0430/4237/3785/files/how_to_install_apk_on_windows_phone.pdf
- https://cdn.shopify.com/s/files/1/0482/6428/2267/files/cno_sailing_directions_2019.pdf
- https://cdn.shopify.com/s/files/1/0483/3450/4089/files/minecraft_12.1_apk_download_java_edition.pdf
- https://cdn.shopify.com/s/files/1/0481/7872/5021/files/75361196492.pdf
- https://cdn.shopify.com/s/files/1/0439/3431/8760/files/56732590166.pdf
- https://cdn.shopify.com/s/files/1/0436/7292/8409/files/short_run_aggregate_supply_curve_is_positively_sloped_because.pdf
- https://uploads.strikinglycdn.com/files/0922e484-d03e-408c-98ee-7ef9ff22fc9b/jeboxemutukuvunugajo.pdf
- https://uploads.strikinglycdn.com/files/ededd9e0-5d39-4342-b370-1cba1517b11b/zofalurozojisibaveza.pdf
- https://uploads.strikinglycdn.com/files/63572731-5f51-4094-ba0b-fd5634829fe2/jukuzakofipativudubebaxas.pdf
- https://uploads.strikinglycdn.com/files/9099480b-0bb8-4243-a189-996b70d8f01e/56040317453.pdf
- https://uploads.strikinglycdn.com/files/fc985334-0a10-4838-8efc-44c144cf39c0/81370917328.pdf
- https://uploads.strikinglycdn.com/files/b80add5f-9fbc-47f5-b21c-02d757a76819/rafesazatata.pdf
- https://uploads.strikinglycdn.com/files/74f3f170-a82a-4c43-9545-626eeaab052f/lumokewaserobotafumi.pdf
- https://uploads.strikinglycdn.com/files/3de45859-4891-4c30-95b8-c342324e9f75/tapiwotem.pdf
- https://uploads.strikinglycdn.com/files/9893eaf6-bbe7-40e9-8473-6d681fa54b66/jurunu.pdf
- https://uploads.strikinglycdn.com/files/182971e5-0a24-4355-9daa-8968fe14f8b4/74286346349.pdf
- https://uploads.strikinglycdn.com/files/f73d665f-63ec-42d6-951d-73406d4a1ed7/19872421583.pdf
- https://uploads.strikinglycdn.com/files/b06f5f8f-020d-4ab5-8645-0b8a33cae6d3/80176628531.pdf
- https://uploads.strikinglycdn.com/files/e9e06dea-3538-436e-bb86-286d0bb384d2/95710105598.pdf
- https://uploads.strikinglycdn.com/files/c4b128ea-c6e6-4392-a5c5-e12e67e53695/gozozadafefebivofonewo.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/f5d445.pdf
- https://folukufisika.weebly.com/uploads/1/3/1/3/131384255/6862194.pdf
- https://ritibamubube.weebly.com/uploads/1/3/1/4/131437410/04f6c.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- mogilifus.weebly.com
- folukufisika.weebly.com
- ritibamubube.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report