SUSPICIOUS — normal_5f9b5a64d85ce.pdf
SUSPICIOUS — normal_5f9b5a64d85ce.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0d123425802c5ba1e91e043b6765be3c20db404f08353308a00218ea846bf8ff - SHA-1:
0bf4894b34b32f303b8f2799f6d4931ed445fad1 - MD5:
af34200a554b3414a929257e7ebf7e78 - ssdeep:
768:fgGzpDRIpp573kYhHoifUDuf3dT7w16u1GO0DA17PK+jJqLrgT1htTiBz4:oGF1IFzlhHoifUq3dw171GjA17PJqC1b - TLSH:
T151319EF310A7DD9C7A8B6F436DE620A99199D74C6132976088C83B3CC4BC7AD7E04961 - Submitted as: normal_5f9b5a64d85ce.pdf
- File type: pdf · Size: 42033 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=how+to+paint+glass+windows, https://uploads.strikinglycdn.com/files/6dd34b6e-f75f-4653-9e84-4683d2e25535/80287683122.pdf, https://cdn-cms.f-static.net/uploads/4367622/normal_5f999df878434.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=how+to+paint+glass+windows
- https://uploads.strikinglycdn.com/files/6dd34b6e-f75f-4653-9e84-4683d2e25535/80287683122.pdf
- https://cdn-cms.f-static.net/uploads/4367622/normal_5f999df878434.pdf
- https://s3.amazonaws.com/desenaz/activities_for_developing_critical_thinking_skills.pdf
- https://s3.amazonaws.com/wilugugo/foloziwukab.pdf
- https://bizevino.weebly.com/uploads/1/3/4/3/134320064/6818308.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f874a288ff0c.pdf
- https://s3.amazonaws.com/megulu/caperucita_roja_en_ingles.pdf
- https://uploads.strikinglycdn.com/files/ed38775c-d05b-430a-9c10-888c7fba6049/xufegijilenerivubazita.pdf
- https://s3.amazonaws.com/zonebon/86228347314.pdf
- https://s3.amazonaws.com/padadutiseni/22740890400.pdf
- https://nuvuxupu.weebly.com/uploads/1/3/4/5/134507381/4021894.pdf
- https://s3.amazonaws.com/pusumowi/data_mining_concepts_and_techniques_solution.pdf
- https://s3.amazonaws.com/gopuze/93995493809.pdf
- https://s3.amazonaws.com/kasuwevovog/34259714806.pdf
- https://s3.amazonaws.com/fefurorobumi/86189537105.pdf
- https://s3.amazonaws.com/zurovajij/firibisafojopuxoki.pdf
- https://s3.amazonaws.com/mokuwanibof/apache_web_server_configuration_in_linux_step_by_step.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- bizevino.weebly.com
- nuvuxupu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report