SUSPICIOUS — normal_5f883e939a3cf.pdf
SUSPICIOUS — normal_5f883e939a3cf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c0b7ccdc901eb6a954a67ec2d04138a58e105a2b591e21c3776756238a9ce8e1 - SHA-1:
32f00b489d03e70fa579b81c1f6179324de70535 - MD5:
d06ae6017e2e007c93588fe5f3456e1c - ssdeep:
1536:+GFpnB1ICZqaSN/uy5sJbkWGPwmHrwrtjMvhxWGQGhc54n:nFpvkawWJbuLspGsVy - TLSH:
T14836AFF31063ED4D7E8B9F93ADD6016A6449CB4871229AA15488377CD57CAFE3F00A02 - Submitted as: normal_5f883e939a3cf.pdf
- File type: pdf · Size: 65236 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=poor+economics+pdf+%25D9%2585%25D8%25AA%25D8%25B1%25D8%25AC%25D9%2585, https://cdn.shopify.com/s/files/1/0435/5879/7471/files/niall_horan_tour_t_shirt.pdf, https://cdn.shopify.com/s/files/1/0440/2790/4165/files/san_jose_ninja_tournament_2018.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=poor+economics+pdf+%25D9%2585%25D8%25AA%25D8%25B1%25D8%25AC%25D9%2585
- https://cdn.shopify.com/s/files/1/0435/5879/7471/files/niall_horan_tour_t_shirt.pdf
- https://cdn.shopify.com/s/files/1/0440/2790/4165/files/san_jose_ninja_tournament_2018.pdf
- https://cdn.shopify.com/s/files/1/0432/5418/6146/files/number_cards_printable.pdf
- https://cdn.shopify.com/s/files/1/0440/9845/3656/files/4398396942.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f870607baf9a.pdf
- https://cdn-cms.f-static.net/uploads/4368251/normal_5f876dc9f20a8.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f8824f82a5cd.pdf
- https://cdn-cms.f-static.net/uploads/4366402/normal_5f871bb211109.pdf
- https://cdn.shopify.com/s/files/1/0434/8713/3860/files/rabubofolo.pdf
- https://cdn.shopify.com/s/files/1/0434/0485/3402/files/46990459601.pdf
- https://cdn.shopify.com/s/files/1/0484/2635/2797/files/48_quart_cooler_igloo.pdf
- https://cdn.shopify.com/s/files/1/0434/7926/9541/files/digisuze.pdf
- https://cdn.shopify.com/s/files/1/0440/4389/4934/files/what_size_package_fits_in_usps_drop_box.pdf
- https://cdn.shopify.com/s/files/1/0499/3413/9546/files/bigo_live_hack_diamond_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0485/1689/0786/files/buduwedupowafiti.pdf
- https://cdn.shopify.com/s/files/1/0432/2535/0301/files/linunotikakexetujixov.pdf
- https://cdn.shopify.com/s/files/1/0430/7619/0361/files/38409039532.pdf
- https://cdn.shopify.com/s/files/1/0435/1954/1416/files/unidad_1_etapa_2_mas_practica_answers.pdf
- https://site-1043487.mozfiles.com/files/1043487/hp_proliant_dl380p_gen8_memory_installation_guide.pdf
- https://site-1042987.mozfiles.com/files/1042987/jasijajefujosemup.pdf
- https://site-1042510.mozfiles.com/files/1042510/24362764588.pdf
- https://site-1037212.mozfiles.com/files/1037212/11815204530.pdf
- https://site-1038872.mozfiles.com/files/1038872/11003929488.pdf
- https://site-1038949.mozfiles.com/files/1038949/zosam.pdf
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1043487.mozfiles.com
- site-1042987.mozfiles.com
- site-1042510.mozfiles.com
- site-1037212.mozfiles.com
- site-1038872.mozfiles.com
- site-1038949.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report