SUSPICIOUS — normal_5f939467ecfa0.pdf
SUSPICIOUS — normal_5f939467ecfa0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
08a310077a8467add544282a101efbe47984a8a2c6b85f20831a0bf465fa35e0 - SHA-1:
2b8fe6af572ed7666310c1ac60b09bee67aa9a9f - MD5:
d79617acfccf5a3c988be39c6dd649da - ssdeep:
768:mgGzpD08BK6dZRH21pfij0kCloYaaoGytYqFChx6/UGsJt4/ePl6lBPBk:zGFI8ldgXIaopYqAh0/wt4mUnPBk - TLSH:
T164339DF30093ED4C7ACF5F136EA735A9614AC38971369B600998772DD0BC6ED2E00966 - Submitted as: normal_5f939467ecfa0.pdf
- File type: pdf · Size: 48083 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=medicine+names+dictionary+pdf, https://kawewadibuporak.weebly.com/uploads/1/3/4/3/134371142/c87f9279.pdf, https://fabuxitewuf.weebly.com/uploads/1/3/4/3/134349615/dc4d9f62.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=medicine+names+dictionary+pdf
- https://kawewadibuporak.weebly.com/uploads/1/3/4/3/134371142/c87f9279.pdf
- https://fabuxitewuf.weebly.com/uploads/1/3/4/3/134349615/dc4d9f62.pdf
- https://jubunukaf.weebly.com/uploads/1/3/1/4/131483214/8317509.pdf
- https://kokexofagisukop.weebly.com/uploads/1/3/2/7/132710589/ruwitawogo_rusajexedav_lusepapa_takibikezuro.pdf
- https://wotufoxak.weebly.com/uploads/1/3/4/3/134308946/62b0cd.pdf
- https://cdn.shopify.com/s/files/1/0432/7063/5676/files/88634007427.pdf
- https://cdn.shopify.com/s/files/1/0502/1827/0905/files/download_messenger_apk_monk.pdf
- https://sovopubi.weebly.com/uploads/1/3/0/7/130775052/lepuzisukawe_judul.pdf
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/nafuvulivorelar.pdf
- https://xanugobolenaz.weebly.com/uploads/1/3/4/3/134371028/6303451.pdf
- https://sipasegeremiraf.weebly.com/uploads/1/3/4/4/134404187/wilomi.pdf
- https://cdn.shopify.com/s/files/1/0430/7111/1330/files/starcraft_2_wings_of_liberty_offline_crack.pdf
- https://cdn.shopify.com/s/files/1/0501/3146/8453/files/classifying_triangles_by_sides_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0497/2786/4993/files/99654932917.pdf
- https://cdn.shopify.com/s/files/1/0498/6801/3723/files/remote_access_iphone_from_android.pdf
- https://cdn.shopify.com/s/files/1/0485/2016/7586/files/85228551351.pdf
- https://s3.amazonaws.com/henghuili-files/jorijenijuzojobugunikevom.pdf
- https://s3.amazonaws.com/sugaguxagu/pigogutigebu.pdf
- https://s3.amazonaws.com/saxefi/vuxinosazururefaketule.pdf
- https://s3.amazonaws.com/subud/aws_athena_documentation.pdf
- https://s3.amazonaws.com/fazujo/50_solidworks_exercises.pdf
- https://s3.amazonaws.com/kavitokolezub/algorithmic_trading_chan.pdf
- https://s3.amazonaws.com/votawawo/apprendre_l_allemand_pour_dbutant_gratuit.pdf
- https://s3.amazonaws.com/pivetuzadujo/lazovojuve.pdf
Embedded domains
- ttraff.ru
- kawewadibuporak.weebly.com
- fabuxitewuf.weebly.com
- jubunukaf.weebly.com
- kokexofagisukop.weebly.com
- wotufoxak.weebly.com
- cdn.shopify.com
- sovopubi.weebly.com
- bizumoku.weebly.com
- xanugobolenaz.weebly.com
- sipasegeremiraf.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report