SUSPICIOUS — normal_5f9370720598d.pdf
SUSPICIOUS — normal_5f9370720598d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
cbaa8a1253f2345fa9677f7ff4fc60cc9e17aff73a769921bd8107f5be2f8341 - SHA-1:
e1b99ec3a3438cc9168f927b435e039b77ba5b60 - MD5:
fd1581616e9d73b23fa766a40abafd4c - ssdeep:
768:jgGzpDOpoPzDGrF4N66ziVN0f6htlv0GSfz:cGFQokUiVN06tlv0GSfz - TLSH:
T1A8308EF350ABDD8DBA4A9B43ADF605595189D388A23BD76018DC772DD4BC2BC7E10820 - Submitted as: normal_5f9370720598d.pdf
- File type: pdf · Size: 38016 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=il+linguaggio+specialistico+del+turismo+nigro+pdf, https://cdn.shopify.com/s/files/1/0496/6914/4739/files/watowetaxav.pdf, https://cdn.shopify.com/s/files/1/0501/8432/3252/files/download_game_uphill_rush_racing_mod_apk.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=il+linguaggio+specialistico+del+turismo+nigro+pdf
- https://cdn.shopify.com/s/files/1/0496/6914/4739/files/watowetaxav.pdf
- https://cdn.shopify.com/s/files/1/0501/8432/3252/files/download_game_uphill_rush_racing_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0496/6708/0356/files/physics_syllabus_o_level.pdf
- https://cdn-cms.f-static.net/uploads/4369173/normal_5f8b4e4b81850.pdf
- https://cdn-cms.f-static.net/uploads/4404122/normal_5f9369b38ef59.pdf
- https://cdn-cms.f-static.net/uploads/4372361/normal_5f8a8d3fa51cf.pdf
- https://uploads.strikinglycdn.com/files/6d209f30-ef61-4b6c-8eb5-130a6ec3b23c/40495087209.pdf
- https://uploads.strikinglycdn.com/files/8a15b9dd-4308-40c9-b8fc-b8a6b2e5411f/mematoravigoxovo.pdf
- https://uploads.strikinglycdn.com/files/0c2ac4bc-15df-4ac4-aeb0-286bb82a9ab3/25048631259.pdf
- https://uploads.strikinglycdn.com/files/b1b99fbb-d154-4d4d-9087-3147abb9cd49/54368612045.pdf
- https://uploads.strikinglycdn.com/files/d9b5660e-5b35-4501-b147-78913bef658b/44590318246.pdf
- https://uploads.strikinglycdn.com/files/8ee7c5b6-79dc-4bd7-a660-c11a792f5c40/dojuxadetivumukubalorebu.pdf
- https://uploads.strikinglycdn.com/files/e2e3840e-2071-4694-9129-98a32d758b80/kikolesejete.pdf
- https://uploads.strikinglycdn.com/files/78ffaf47-7bf1-4ba9-b143-09e1d2e6552b/78427237924.pdf
- https://uploads.strikinglycdn.com/files/c521b7ee-7266-46db-9106-b43cb4194c4a/winibom.pdf
- https://s3.amazonaws.com/wilugugo/86889933906.pdf
- https://s3.amazonaws.com/limewub/tidabefigebogetolezib.pdf
- https://s3.amazonaws.com/zuxadol/31224328691.pdf
- https://s3.amazonaws.com/wonoti/toxaxuvepeb.pdf
- https://s3.amazonaws.com/rupatojuko/milan_classification_of_salivary_gland_tumors.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report