SUSPICIOUS — normal_5f8737048c9d7.pdf
SUSPICIOUS — normal_5f8737048c9d7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0b727abe0f72eadf7dba43ae9598808a4e6b1db16f3a899c7de139764de6a7fc - SHA-1:
084774ff97e13a1424fef56d6881ca743ff1360b - MD5:
d0d743afb2e3aaac1e35e4ff780a2f88 - ssdeep:
768:jSgGzpD0Ep8vO0Ev7IDmMUnOcrIZyT1+sRVOPtbfKnWrjbllD6q9v4d:bGF3pVLrF1+sRVOPtDKnWh9v4d - TLSH:
T17A317EF340A3EC8C7A8F9F039DAB156E9186D78DA136A650458C673DD0BC6EC6E00D61 - Submitted as: normal_5f8737048c9d7.pdf
- File type: pdf · Size: 41188 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=nox+android+emulator+windows+xp, https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/bawap.pdf, https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/jibigamefomoni.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=nox+android+emulator+windows+xp
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/bawap.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/jibigamefomoni.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/laresisif_kigadebokenub_bajutinerid.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/6ec94.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/f1dfc27.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/1441493.pdf
- https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/rezukiwamid.pdf
- https://cdn.shopify.com/s/files/1/0268/8470/2386/files/new_wave_cable_channel_guide.pdf
- https://cdn.shopify.com/s/files/1/0500/4155/3046/files/75197810098.pdf
- https://cdn.shopify.com/s/files/1/0438/2588/9442/files/xomogen.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/zegomotagenig.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/9fa7699.pdf
- https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/difoduwebuvim.pdf
- https://cdn.shopify.com/s/files/1/0432/2548/1379/files/the_gorgeous_nothings_emily_dickinsons_envelope_poems.pdf
- https://cdn.shopify.com/s/files/1/0498/7279/7857/files/48007732876.pdf
- https://cdn.shopify.com/s/files/1/0266/9094/5194/files/ridiwunixedajojinisat.pdf
- https://cdn.shopify.com/s/files/1/0428/3770/4867/files/losuwavininepovaso.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/4e62bca4882baf.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/gapovowumepekegosiza.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- jatorogerujew.weebly.com
- fijojonibiw.weebly.com
- genigudepa.weebly.com
- kabudededawizo.weebly.com
- jufaxexave.weebly.com
- xojerajap.weebly.com
- vikumeniwexawud.weebly.com
- cdn.shopify.com
- dutitujazekap.weebly.com
- jawowigo.weebly.com
- jukafubu.weebly.com
- nukevokisoget.weebly.com
- besiwalufeg.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report