SUSPICIOUS — normal_5f88ec8a3507e.pdf
SUSPICIOUS — normal_5f88ec8a3507e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
17dfe318ab54f0f27fab455afb69537737bebc2c5e8e7eabdcf26cec8d4be7bc - SHA-1:
da1f79afc7dfd699ae1be4c865cd9c62e16cb368 - MD5:
57a3c89b37c8bc2a0540bb9f1318396a - ssdeep:
768:cxgGzpDjepS3xfWXEOQVgTyO2iix4eVcecPIYBNdqk0:XGFOpoFMR3ix0PIYB7qk0 - TLSH:
T153317EF350A7ED8C7A8AAF07ADBA1158614EC7886036D760454C673D90BC6FE3E00D51 - Submitted as: normal_5f88ec8a3507e.pdf
- File type: pdf · Size: 42259 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=terraria+download+android+1.3, https://uploads.strikinglycdn.com/files/80b82032-5423-406e-9a80-a21afd5b6f99/31857009552.pdf, https://uploads.strikinglycdn.com/files/4856ae9b-8bf6-47aa-809f-6d5c0a97573e/jodipototabirafafi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=terraria+download+android+1.3
- https://uploads.strikinglycdn.com/files/80b82032-5423-406e-9a80-a21afd5b6f99/31857009552.pdf
- https://uploads.strikinglycdn.com/files/4856ae9b-8bf6-47aa-809f-6d5c0a97573e/jodipototabirafafi.pdf
- https://uploads.strikinglycdn.com/files/d21148b3-2cca-4cdb-8da5-e7067f728948/zefuponezuxotigakef.pdf
- https://uploads.strikinglycdn.com/files/f596a7e7-75d9-4058-bcfd-429046abc4cb/71007586069.pdf
- https://uploads.strikinglycdn.com/files/e3c07a03-cdc7-44c3-9908-91306deb9eb6/nupifipavokovozonofive.pdf
- https://uploads.strikinglycdn.com/files/f39e84c6-764b-4d4f-96ba-a0d00af09502/vexuwigevedonusafewufonap.pdf
- https://uploads.strikinglycdn.com/files/31f11c2c-130b-40cd-a194-6e7bfcda4344/54179543607.pdf
- https://uploads.strikinglycdn.com/files/394c1c0c-ed86-4c87-b2df-4e62e5183a33/vimuzurimoxiretir.pdf
- https://uploads.strikinglycdn.com/files/62c971dc-3878-4e25-bfac-6f97683a88e4/gebulovujomowel.pdf
- https://uploads.strikinglycdn.com/files/12ea1783-0a92-4ef3-baed-97a9141d6f38/31554066002.pdf
- https://uploads.strikinglycdn.com/files/100f0e39-6870-474e-8641-d91b90777856/61408912272.pdf
- https://uploads.strikinglycdn.com/files/a48a8f5a-0d67-4312-b160-0e8021ea46e9/88394694374.pdf
- https://uploads.strikinglycdn.com/files/615a9a76-8059-4acb-beef-c7901669e412/54674667685.pdf
- https://uploads.strikinglycdn.com/files/258148d1-ff65-4a67-bfd2-ea8348704dbe/81582144970.pdf
- https://uploads.strikinglycdn.com/files/2d2a4ff4-4d2f-4572-bb45-bf1c396fdfb0/16725783180.pdf
- https://uploads.strikinglycdn.com/files/bbb79fc2-e8bf-48ba-9b65-2bd16ac82914/45402921357.pdf
- https://uploads.strikinglycdn.com/files/1af2c6d4-680e-4399-b0f5-767798017f40/43599932230.pdf
- https://sonilotosoj.weebly.com/uploads/1/3/1/3/131379329/505aa.pdf
- https://dumejolizaxoko.weebly.com/uploads/1/3/0/8/130814858/gabomivadi.pdf
- https://kusanogiwaxug.weebly.com/uploads/1/3/0/8/130873987/6089907cad1d787.pdf
- https://site-1043167.mozfiles.com/files/1043167/mirevajidijadolexapowu.pdf
- https://site-1036907.mozfiles.com/files/1036907/wobelesowi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- sonilotosoj.weebly.com
- dumejolizaxoko.weebly.com
- kusanogiwaxug.weebly.com
- site-1043167.mozfiles.com
- site-1036907.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report