SUSPICIOUS — normal_5f9299002a56b.pdf
SUSPICIOUS — normal_5f9299002a56b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
055d1a96e541034b23edc9fbb68cfaa0f8cdb9cb71f680e9aec2eeef660cd7db - SHA-1:
08221058befd72ca2b808df67356a080cda71138 - MD5:
73f3c7e4c27170e212a345d4e9bae4ad - ssdeep:
768:pgGzpDqpj2pWb23moRsAE/mc0xlB1cVywhal55p08q9+aBLIzRxB3hc9p:KGF+pVhoRsH2x9WyH77SBatMp - TLSH:
T136349DF35097ECDC2A8B9B079AAB14A9914AC38C71369B7044CC372DD43CAFD6E10A55 - Submitted as: normal_5f9299002a56b.pdf
- File type: pdf · Size: 53523 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=dylan+dog+case+files+pdf, https://uploads.strikinglycdn.com/files/60b3069e-3cb1-4f9a-988a-66e855e66867/89097747415.pdf, https://uploads.strikinglycdn.com/files/1bb77b09-3b7c-49e1-91dd-d87caf84ba7f/kizasizelozedasarozup.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=dylan+dog+case+files+pdf
- https://uploads.strikinglycdn.com/files/60b3069e-3cb1-4f9a-988a-66e855e66867/89097747415.pdf
- https://uploads.strikinglycdn.com/files/1bb77b09-3b7c-49e1-91dd-d87caf84ba7f/kizasizelozedasarozup.pdf
- https://uploads.strikinglycdn.com/files/b822a169-7c5c-4929-8780-c0f7fe95c4d0/javukasidaxobejagobuko.pdf
- https://uploads.strikinglycdn.com/files/b16110d7-3edb-48fb-86f9-9a4eb4576f40/dunazoxusudiwuzarimidor.pdf
- https://uploads.strikinglycdn.com/files/4b725f2a-f11c-4ffe-ba74-c3f44266e95c/70828066144.pdf
- https://uploads.strikinglycdn.com/files/7f80c532-4f74-4b5e-a466-51caa5c4d56a/famamafuwukepamejuxuge.pdf
- https://uploads.strikinglycdn.com/files/a1edd5e4-01e3-42df-9ebc-bb1e732cb23e/zotupinatiz.pdf
- https://uploads.strikinglycdn.com/files/71104d13-067e-4dbd-bcf4-cd4544849a8b/35951114392.pdf
- https://uploads.strikinglycdn.com/files/064e29bb-f78e-44e3-b4f8-383467c690ca/13947262554.pdf
- https://uploads.strikinglycdn.com/files/94eb2db4-80b4-40ac-84d6-3e20411be8e2/96043992909.pdf
- https://uploads.strikinglycdn.com/files/4ee05388-0003-4052-b3be-913e633b28bc/hack_gu_rebirth_walkthrough.pdf
- https://cdn.shopify.com/s/files/1/0436/1804/2018/files/texas_toast_frozen_garlic_bread_instructions.pdf
- https://cdn.shopify.com/s/files/1/0505/0184/5162/files/plane_geometry_lecture_notes.pdf
- https://jenafowumavadas.weebly.com/uploads/1/3/1/4/131437472/a14243550ea.pdf
- https://kafasomawupi.weebly.com/uploads/1/3/0/7/130775431/wewuwokumapobo.pdf
- https://junafoxotoroj.weebly.com/uploads/1/3/0/7/130738975/366582.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/resesemeni.pdf
- https://moguvikob.weebly.com/uploads/1/3/0/8/130874292/babelowezituro.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tudaf_pizokokavil_nupepalo.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/kekifafonusidit.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/xodizefovi_zuzabunajuka_bejitoxu_jixelaxis.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- jenafowumavadas.weebly.com
- kafasomawupi.weebly.com
- junafoxotoroj.weebly.com
- vopevejefed.weebly.com
- moguvikob.weebly.com
- genigudepa.weebly.com
- tivakoxidedopa.weebly.com
- fuparududewon.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report