SUSPICIOUS — normal_5f8beefa823bc.pdf
SUSPICIOUS — normal_5f8beefa823bc.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
eeefb88bc19aaface3c0631cc5a39d81e1a8990aba9d3b936d02b82ce8da4d49 - SHA-1:
bfb23dac64f8b81553539188a911667cb943bd87 - MD5:
6083b0291413b3752d4aeea95d9e8eed - ssdeep:
768:iTgGzpDLpeMUq3VayAS283+VcVS/SF4ttVEMhh3kk04yP9GBAs+q6/6AeqSs/CE:zGF/peoV2dRLyP9Y+6Aels/CE - TLSH:
T1FF327DF350B7DC4C7A8E5B53ADA71459944AC7887233A6A0048C772CC5BCAFE3E41A61 - Submitted as: normal_5f8beefa823bc.pdf
- File type: pdf · Size: 45637 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=android+background+service+notification+example+github, https://cdn.shopify.com/s/files/1/0435/9038/5823/files/free_fire_mod_apk_unlimited_diamonds_download.pdf, https://cdn.shopify.com/s/files/1/0437/3220/5722/files/kikamatafexu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=android+background+service+notification+example+github
- https://cdn.shopify.com/s/files/1/0435/9038/5823/files/free_fire_mod_apk_unlimited_diamonds_download.pdf
- https://cdn.shopify.com/s/files/1/0437/3220/5722/files/kikamatafexu.pdf
- https://cdn.shopify.com/s/files/1/0428/6870/3398/files/the_christmas_card_cast.pdf
- https://cdn.shopify.com/s/files/1/0499/3122/3202/files/ixl_answer_key_algebra_1.pdf
- https://cdn.shopify.com/s/files/1/0482/0264/5658/files/tecnica_zero_g_guide.pdf
- https://uploads.strikinglycdn.com/files/27f4a9a0-43be-46c7-a795-18ede1fb5c85/57471201097.pdf
- https://uploads.strikinglycdn.com/files/618d4cfc-484e-4951-a60d-2dff9e6e1687/9072197313.pdf
- https://uploads.strikinglycdn.com/files/685c8872-599d-4613-80f6-f0e77de152fb/35223858224.pdf
- https://cdn.shopify.com/s/files/1/0483/9148/7640/files/crowders_mountain_state_park_map.pdf
- https://cdn.shopify.com/s/files/1/0481/3340/6871/files/94767071989.pdf
- https://cdn.shopify.com/s/files/1/0435/3071/5288/files/zemurewovis.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/1346883.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/8997904d1d1210.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/3257372.pdf
- https://naxizugopigonav.weebly.com/uploads/1/3/1/4/131408516/pewezetej.pdf
- https://renesixedobalew.weebly.com/uploads/1/3/0/9/130969137/930e2b3.pdf
- https://uploads.strikinglycdn.com/files/6acfeccc-2af5-411e-88d3-9d65be67dba3/rasozulexogewilamupoza.pdf
- https://uploads.strikinglycdn.com/files/002027ce-ef63-4d64-a864-05ad8d8d562c/wafiwifegoken.pdf
- https://cdn-cms.f-static.net/uploads/4368736/normal_5f8819d9a1706.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f87f030a76f7.pdf
- https://cdn-cms.f-static.net/uploads/4369629/normal_5f8915dac51b0.pdf
- https://cdn-cms.f-static.net/uploads/4373999/normal_5f892e63be909.pdf
- https://cdn-cms.f-static.net/uploads/4366659/normal_5f8894e7ed515.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- boguvetasitob.weebly.com
- jamuseramomuf.weebly.com
- vuxozajuje.weebly.com
- naxizugopigonav.weebly.com
- renesixedobalew.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report