MALICIOUS — normal_5f8b554a81320.pdf
MALICIOUS — normal_5f8b554a81320.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 3 of 54 detection engines flagged it.
Identification
- SHA-256:
e3a74bdaa14d759047640eb51f290c5acb148a01a0208422fda9f6ff3b57ce10 - SHA-1:
dd85cec169fc7264987f1bb95233149844e3cc96 - MD5:
03eccfe7384f16735a72761080d82f68 - ssdeep:
1536:6GF/pdsM0EN9hX9qwDLZVKrvzGcI1uNKJkEAId/Rev:jF/prBNVqwRYrrzIcEA1 - TLSH:
T14F35BFF310A3ED8C7A4EEF47ADA71169544AC68C613397A050CC6B1CD17C6FEAE10690 - Submitted as: normal_5f8b554a81320.pdf
- File type: pdf · Size: 57948 bytes
- Verdict: malicious (70/100)
Detections (3 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://ggtraff.ru/123?keyword=bose+wireless+earbuds+user+manual, https://cdn-cms.f-static.net/uploads/4368249/normal_5f8a3f7e4e038.pdf, https://cdn-cms.f-static.net/uploads/4366335/normal_5f874fff0ce90.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=bose+wireless+earbuds+user+manual
- https://cdn-cms.f-static.net/uploads/4368249/normal_5f8a3f7e4e038.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f874fff0ce90.pdf
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f88acb4580c8.pdf
- https://cdn-cms.f-static.net/uploads/4376609/normal_5f8b0a5d336e0.pdf
- https://uploads.strikinglycdn.com/files/31b7b414-c8a8-491e-b3b9-76e3886a6868/5191336114.pdf
- https://uploads.strikinglycdn.com/files/35ae75ec-03b5-4648-8fcd-6b9e7b116c5f/40732234782.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f88638ff1586.pdf
- https://cdn-cms.f-static.net/uploads/4372355/normal_5f89c27cba6f8.pdf
- https://cdn-cms.f-static.net/uploads/4366000/normal_5f89671c26e68.pdf
- https://cdn.shopify.com/s/files/1/0501/9936/3764/files/aapko_humse_bichde_hue_ek_zamana_mp3.pdf
- https://cdn.shopify.com/s/files/1/0496/6875/1523/files/87885373631.pdf
- https://cdn.shopify.com/s/files/1/0437/9282/6517/files/18177986444.pdf
- https://cdn.shopify.com/s/files/1/0503/8309/3910/files/befuxodavogutaxaboxuva.pdf
- https://cdn.shopify.com/s/files/1/0482/8210/8065/files/18339645375.pdf
- https://uploads.strikinglycdn.com/files/6731ed52-b5fb-487b-b29d-a11bae1941f2/22155644153.pdf
- https://uploads.strikinglycdn.com/files/23ab760f-1b1d-4553-8c88-c5dc2bd4c931/10810615740.pdf
- https://uploads.strikinglycdn.com/files/930bc1bd-e370-492b-b8dd-5f36ed6cabb4/vivetupulala.pdf
- https://uploads.strikinglycdn.com/files/36f6e916-6332-4a1f-bc42-171e4908f480/tibaziva.pdf
- https://uploads.strikinglycdn.com/files/8f34c07b-4839-47a7-a6de-47a4e8b99c96/vuditixunagamagijemat.pdf
- https://uploads.strikinglycdn.com/files/55e4cd98-e3a4-44bf-aff8-d39df9b4ac9b/80911966958.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report