SUSPICIOUS — normal_5f87e46f2c110.pdf
SUSPICIOUS — normal_5f87e46f2c110.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ddbb05802053f24a1cb365e3ed41f48a29ac9eb060bc3d37ae19fb890192ec05 - SHA-1:
fdde9ec1719811b4c2a8a07e3927719422c1aaa1 - MD5:
b02d3cabfdc4d1d4bcadc798737b1d55 - ssdeep:
768:YgGzpD2p21cAZBsbcWrOBTvwwf/8Hcxe8NU6sbB4f86HKXpDzY3WjCHcV8RagxSm:1GFypkw0JA4f86qXpDk3GG3agkm - TLSH:
T1DA339EF3109BDC4C7A8F6F07AE97115E908AD7896237D7A444887A2DC07C6ED3E10661 - Submitted as: normal_5f87e46f2c110.pdf
- File type: pdf · Size: 49633 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=a+thousand+years+sheet+music+pdf+guitar, https://cdn-cms.f-static.net/uploads/4366408/normal_5f87a28b373bb.pdf, https://cdn-cms.f-static.net/uploads/4366623/normal_5f8733862179b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=a+thousand+years+sheet+music+pdf+guitar
- https://cdn-cms.f-static.net/uploads/4366408/normal_5f87a28b373bb.pdf
- https://cdn-cms.f-static.net/uploads/4366623/normal_5f8733862179b.pdf
- https://cdn-cms.f-static.net/uploads/4365553/normal_5f87bbe1ef7d0.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f87136c3b35e.pdf
- https://cdn-cms.f-static.net/uploads/4369160/normal_5f87a3754280d.pdf
- https://site-1039517.mozfiles.com/files/1039517/96582724090.pdf
- https://site-1037907.mozfiles.com/files/1037907/46658002966.pdf
- https://site-1039800.mozfiles.com/files/1039800/wevotazorezofezebuz.pdf
- https://cdn.shopify.com/s/files/1/0428/7404/4579/files/28245600106.pdf
- https://cdn.shopify.com/s/files/1/0430/7222/5442/files/63282971283.pdf
- https://cdn.shopify.com/s/files/1/0502/8046/4578/files/horror_story_books_in_tamil.pdf
- https://cdn.shopify.com/s/files/1/0493/5240/9247/files/rubbermaid_cooler_hinges.pdf
- https://cdn.shopify.com/s/files/1/0485/2645/9035/files/baseball_field_diagram_position_numbers.pdf
- https://cdn.shopify.com/s/files/1/0431/7652/5984/files/should_college_athletes_be_paid_pros_and_cons_espn.pdf
- https://uploads.strikinglycdn.com/files/87cec736-28fe-43ed-bd8c-24d5b08e72a8/13207972352.pdf
- https://uploads.strikinglycdn.com/files/b22e6280-9ac1-4741-b9c5-02b52ceee4d8/19287604746.pdf
- https://uploads.strikinglycdn.com/files/d5047fc4-ca03-45d9-9602-c2080b420dec/nenimabazixodelenizobitan.pdf
- https://uploads.strikinglycdn.com/files/2b09ff42-5dc2-4dff-bb5e-7a507f613a50/vojokegukuju.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/7254862.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/gajame.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/busixakowun_zefisuni.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/4e0d994f.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/nukexifepejisox.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- site-1039517.mozfiles.com
- site-1037907.mozfiles.com
- site-1039800.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- taxajadotediru.weebly.com
- fadusoga.weebly.com
- jakedekokobara.weebly.com
- genigudepa.weebly.com
- dimaxafazeza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report