SUSPICIOUS — normal_5f876db2cb696.pdf
SUSPICIOUS — normal_5f876db2cb696.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f39e7210a9f1e45655e793dae6edcf5a3c2bad5c487cee2ec55c638ba58d4c76 - SHA-1:
6724682fbe5f8d220064c0ec2672561378aa7354 - MD5:
a7d3a2be55596a7c2600abcb3d090d3e - ssdeep:
1536:PGF2pdeDNovBLVxhSZ/aLoFDE8NiNlHww:+F2pNphVLoFt2L - TLSH:
T1BD33AEF314D7ED4CBA866B039DAA02691089C3CD2137E7904988362DD4BC6FDBE54E61 - Submitted as: normal_5f876db2cb696.pdf
- File type: pdf · Size: 51940 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=luigi%2527s+mansion+3+gem+guide+10f, https://site-1040785.mozfiles.com/files/1040785/39034126150.pdf, https://site-1039649.mozfiles.com/files/1039649/torseur_statique_exercices_corrigs.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=luigi%2527s+mansion+3+gem+guide+10f
- https://site-1040785.mozfiles.com/files/1040785/39034126150.pdf
- https://site-1039649.mozfiles.com/files/1039649/torseur_statique_exercices_corrigs.pdf
- https://site-1042931.mozfiles.com/files/1042931/55067319696.pdf
- https://site-1039999.mozfiles.com/files/1039999/figekuzepuromubi.pdf
- https://site-1039577.mozfiles.com/files/1039577/nobumebudevijowab.pdf
- https://uploads.strikinglycdn.com/files/dd7b2703-2678-437a-a9a7-69e1de1c838d/1106287288.pdf
- https://uploads.strikinglycdn.com/files/05f9a468-b7c2-44e2-8ac7-f062bb0b9c88/povadamuzuvositu.pdf
- https://uploads.strikinglycdn.com/files/41eb15d6-6a0a-4372-a791-80d714f1a4ba/fasowepedekurexe.pdf
- https://cdn.shopify.com/s/files/1/0498/4864/7835/files/39049014828.pdf
- https://cdn.shopify.com/s/files/1/0266/8160/6319/files/53872147310.pdf
- https://cdn.shopify.com/s/files/1/0440/5411/8550/files/outlearning_the_wolves.pdf
- https://uploads.strikinglycdn.com/files/0b7eaeb4-bc11-45d5-98f3-140e4d03974d/71841646876.pdf
- https://uploads.strikinglycdn.com/files/47feabb0-ad3a-4bc2-b55f-4dc90a6b6f43/gajatesuzogulomelesuxebi.pdf
- https://uploads.strikinglycdn.com/files/5644a856-ef57-4adc-ad54-7845ee050b0a/34698114269.pdf
- https://uploads.strikinglycdn.com/files/a11676ed-657f-4483-b1f4-b33756c74ddb/raxebulivibatelosumij.pdf
- https://uploads.strikinglycdn.com/files/02b0447c-3216-48bb-a221-f3872c7ca170/99818962454.pdf
- https://uploads.strikinglycdn.com/files/33180701-cc3e-4b0b-9b6c-fafde4df4419/4834776923.pdf
- https://uploads.strikinglycdn.com/files/f8697b26-6337-4dbd-942b-53e5b84b3fa1/koxilaxamerinomurenener.pdf
- https://uploads.strikinglycdn.com/files/b329d0d0-8565-45c8-a7d6-e10eed3903dd/fisusutirajivesovimamut.pdf
- https://nogafuku.weebly.com/uploads/1/3/2/8/132815296/luvavedefafa.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/mevobenevivar.pdf
- https://besavikeneg.weebly.com/uploads/1/3/2/8/132815808/9220672.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/tugokeg.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/xojajuv-mitegejitokuxig.pdf
Embedded domains
- ggtraff.ru
- site-1040785.mozfiles.com
- site-1039649.mozfiles.com
- site-1042931.mozfiles.com
- site-1039999.mozfiles.com
- site-1039577.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- nogafuku.weebly.com
- kelobutino.weebly.com
- besavikeneg.weebly.com
- vozunutav.weebly.com
- gimejexoxixaza.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report