SUSPICIOUS — normal_5f88d5e8acb16.pdf
SUSPICIOUS — normal_5f88d5e8acb16.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
dfd7fcdbf34e7eb1f523913ac2766629721e10a019a46b9c66d8bbd1d6937402 - SHA-1:
bebb084f74350634a3b3d6ba42c2b10356bce1c1 - MD5:
367618e14de2cf2cf230e34e48b743dc - ssdeep:
768:igGzpD1peZKHEIXvZvCQur4vEKJjqzhjpyWwZi0Wi:/GF5pYdrcLW9VhwU0Wi - TLSH:
T12D308DF360A7FD8C7A8A9F036EEB016D5089D388A166D2A0148C776DD07C6FC3E00961 - Submitted as: normal_5f88d5e8acb16.pdf
- File type: pdf · Size: 38485 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=yaesu+ft+1000mp+manual, https://cdn.shopify.com/s/files/1/0482/0910/0957/files/9521243771.pdf, https://cdn.shopify.com/s/files/1/0480/9218/4740/files/31492538516.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=yaesu+ft+1000mp+manual
- https://cdn.shopify.com/s/files/1/0482/0910/0957/files/9521243771.pdf
- https://cdn.shopify.com/s/files/1/0480/9218/4740/files/31492538516.pdf
- https://cdn.shopify.com/s/files/1/0476/8052/0358/files/dialectic_of_sex.pdf
- https://site-1038460.mozfiles.com/files/1038460/21932237569.pdf
- https://site-1045404.mozfiles.com/files/1045404/jexurufowogiwidarimepet.pdf
- https://site-1039209.mozfiles.com/files/1039209/22843347124.pdf
- https://site-1043669.mozfiles.com/files/1043669/48254167969.pdf
- https://site-1039549.mozfiles.com/files/1039549/69860530764.pdf
- https://site-1045364.mozfiles.com/files/1045364/wirisida.pdf
- https://site-1040373.mozfiles.com/files/1040373/42604146526.pdf
- https://cdn.shopify.com/s/files/1/0462/7342/9661/files/pewopigokataramajagatopir.pdf
- https://cdn.shopify.com/s/files/1/0435/3127/2351/files/96621437278.pdf
- https://cdn.shopify.com/s/files/1/0494/7522/3719/files/weretejaxides.pdf
- https://cdn.shopify.com/s/files/1/0397/9332/8315/files/pompeii_guide_book_and_map.pdf
- https://uploads.strikinglycdn.com/files/edfbc436-d3bb-47a5-952b-c701b96e4cf3/jojafo.pdf
- https://uploads.strikinglycdn.com/files/d714b587-a746-4dbe-89ba-046e69cdafe1/tejutafinikavagepoxa.pdf
- https://topodomero.weebly.com/uploads/1/3/2/6/132696018/07983d31e.pdf
- https://xubuvene.weebly.com/uploads/1/3/1/3/131380433/4843545.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/sulifip_bimewu_wevobami_fivixibileso.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1038460.mozfiles.com
- site-1045404.mozfiles.com
- site-1039209.mozfiles.com
- site-1043669.mozfiles.com
- site-1039549.mozfiles.com
- site-1045364.mozfiles.com
- site-1040373.mozfiles.com
- uploads.strikinglycdn.com
- topodomero.weebly.com
- xubuvene.weebly.com
- nudojafobedem.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report