SUSPICIOUS — normal_5f86f85a24e01.pdf
SUSPICIOUS — normal_5f86f85a24e01.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f3c91163f86c474f7f779ca7e70bd022a4ee8c4fb40cb36652004cb6dc57c94d - SHA-1:
bbab1466c104114e521736b051059e28c84cf56f - MD5:
34c3175834629f12fae8e45b5ffcaf0b - ssdeep:
768:9gGzpD8pHiS85DDZaVKzU7pLxwXgQ0tQ96Ji8W9LB9b8NdtAcXwX:+GFYpH7MzU7pLxQsJTU6hAcXwX - TLSH:
T1E131BEF740A7DD8CB686AF079DAA19596046D38CA1735A7058C8372DC4B86ECAF11A30 - Submitted as: normal_5f86f85a24e01.pdf
- File type: pdf · Size: 42773 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=love+of+my+life+piano+music+pdf, https://cdn-cms.f-static.net/uploads/4365567/normal_5f86f6ae2e7e2.pdf, https://cdn-cms.f-static.net/uploads/4366011/normal_5f86f6356e36c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=love+of+my+life+piano+music+pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f86f6ae2e7e2.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f86f6356e36c.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f86f749e8983.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f86f5fd2a32a.pdf
- https://cdn-cms.f-static.net/uploads/4365636/normal_5f86f4cca4cb4.pdf
- https://site-1043245.mozfiles.com/files/1043245/zibetigi.pdf
- https://site-1039661.mozfiles.com/files/1039661/sonowero.pdf
- https://site-1048536.mozfiles.com/files/1048536/jurakuledopotogusidilil.pdf
- https://site-1045346.mozfiles.com/files/1045346/nafuxukanomego.pdf
- https://site-1038527.mozfiles.com/files/1038527/gafumawukaj.pdf
- https://site-1040282.mozfiles.com/files/1040282/suzozalev.pdf
- https://site-1036981.mozfiles.com/files/1036981/sumozejidokufizuki.pdf
- https://site-1044163.mozfiles.com/files/1044163/xekuxumunulo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- site-1043245.mozfiles.com
- site-1039661.mozfiles.com
- site-1048536.mozfiles.com
- site-1045346.mozfiles.com
- site-1038527.mozfiles.com
- site-1040282.mozfiles.com
- site-1036981.mozfiles.com
- site-1044163.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report