SUSPICIOUS — normal_5f88411912a79.pdf
SUSPICIOUS — normal_5f88411912a79.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d608574ccc24614bc15999b82f846776da7bfa627aea988244c8d246baf74f83 - SHA-1:
12d3f62d3ed3e93c18a17c055776f09e3a2a89c7 - MD5:
56b93ca09a2dccc74ae8612548e44c57 - ssdeep:
768:ogGzpDie/dXiacA6F4R9zbFoWI33fXEJP4KvlVlcu8KNHNOe5oEQGP5y7wT4WfBl:lGFOeUWI3PXEV4ylVKue+DQGPMfUN - TLSH:
T134328FF31067EDCC7A8B6F47ADAA1199904BD78C222597B110C8766CC8BC5FD7E10A21 - Submitted as: normal_5f88411912a79.pdf
- File type: pdf · Size: 46971 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=wine+dark+sea+score+pdf, https://site-1042883.mozfiles.com/files/1042883/19217240717.pdf, https://site-1043669.mozfiles.com/files/1043669/taxeniximuzi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=wine+dark+sea+score+pdf
- https://site-1042883.mozfiles.com/files/1042883/19217240717.pdf
- https://site-1043669.mozfiles.com/files/1043669/taxeniximuzi.pdf
- https://site-1043332.mozfiles.com/files/1043332/43381149772.pdf
- https://site-1043259.mozfiles.com/files/1043259/48747847985.pdf
- https://site-1039508.mozfiles.com/files/1039508/xotakenuzupuza.pdf
- https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/2833280.pdf
- https://cdn-cms.f-static.net/uploads/4369150/normal_5f87a9f3d959e.pdf
- https://cdn-cms.f-static.net/uploads/4366961/normal_5f8755e9e12f9.pdf
- https://cdn-cms.f-static.net/uploads/4367903/normal_5f876e1b05215.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f877893c0355.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/de1873099dc7.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/bagatazojiz_sidatasofugugor_sofaxazute_gureluf.pdf
- https://polabufasol.weebly.com/uploads/1/3/2/8/132814050/812f952889b75.pdf
- https://uploads.strikinglycdn.com/files/77590379-f98f-45e2-90ce-9589f45d85eb/zegopiwokitavenawapukibo.pdf
- https://uploads.strikinglycdn.com/files/36f157e0-4666-4c6d-8d96-b04722d95e6b/wapijabinejufono.pdf
- https://uploads.strikinglycdn.com/files/8696dbe5-54a3-4118-bfcc-6c55f94f4d3f/92429988057.pdf
- https://uploads.strikinglycdn.com/files/25339b2f-9311-41cb-a1db-ecd370bbfcb1/lufuxaxazobipizizaso.pdf
- https://uploads.strikinglycdn.com/files/e5bf7e9d-7391-41ce-b1e1-3e100ea638ac/13412073250.pdf
- https://cdn.shopify.com/s/files/1/0428/6952/2599/files/geniririr.pdf
- https://cdn.shopify.com/s/files/1/0434/0373/9294/files/chavez_elementary_school.pdf
- https://cdn.shopify.com/s/files/1/0439/4313/3352/files/rinatat.pdf
- https://cdn.shopify.com/s/files/1/0482/3118/6589/files/89964181249.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- site-1042883.mozfiles.com
- site-1043669.mozfiles.com
- site-1043332.mozfiles.com
- site-1043259.mozfiles.com
- site-1039508.mozfiles.com
- vixijusodu.weebly.com
- cdn-cms.f-static.net
- kelobutino.weebly.com
- genigudepa.weebly.com
- polabufasol.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report