SUSPICIOUS — normal_5fa42da06facf.pdf
SUSPICIOUS — normal_5fa42da06facf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
2538a245990462c63b58263d26fe011a60bdc77ee58f90f1b8b3c6860ce45655 - SHA-1:
2b96700614318f3f21d25674f9d499515daaaee5 - MD5:
8ab490c88e37dd799aa8234a2be222f5 - ssdeep:
768:ZgGzpDj4Yvaj/+tvGhP0VR6BmaezEniq7dWgWcCZZmbsTZu4bOdwxEc:aGFP4Yyjmteh2GmaeyTWcC2bs8kewxEc - TLSH:
T1AA32BEF7A1B7EC8C7A8AAF275DE615596146D74820329AA048C8733DC5BC2BE2F50910 - Submitted as: normal_5fa42da06facf.pdf
- File type: pdf · Size: 47056 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=drilling+ceramic+tiles, https://cdn-cms.f-static.net/uploads/4365553/normal_5f8a7133a707f.pdf, https://uploads.strikinglycdn.com/files/cf993a93-0758-44c8-b0fb-c0f429780576/4_prong_to_3_prong_dryer_adapter_ace_hardware.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=drilling+ceramic+tiles
- https://cdn-cms.f-static.net/uploads/4365553/normal_5f8a7133a707f.pdf
- https://uploads.strikinglycdn.com/files/cf993a93-0758-44c8-b0fb-c0f429780576/4_prong_to_3_prong_dryer_adapter_ace_hardware.pdf
- https://kebekeloku.weebly.com/uploads/1/3/4/6/134639455/c3426d.pdf
- https://waxojokizubow.weebly.com/uploads/1/3/4/4/134482073/c9f23184bac5bb3.pdf
- https://uploads.strikinglycdn.com/files/3de5273d-c1cc-4393-8acf-8205fa90f97f/xumezekovu.pdf
- https://uploads.strikinglycdn.com/files/3494dc52-09ef-4da1-8687-4e7a84bb35ba/dnd_character_sheet_creation_guide.pdf
- https://s3.amazonaws.com/ribowexulo/3348463095.pdf
- https://tisatazufewuvo.weebly.com/uploads/1/3/1/1/131163687/vukitigofivixor.pdf
- https://bivitomelonex.weebly.com/uploads/1/3/4/4/134491730/jakudidexivan_damubuvi.pdf
- https://uploads.strikinglycdn.com/files/34f1927d-a995-4f03-825c-0b842a889e97/wogakodi.pdf
- https://s3.amazonaws.com/banula/24260441922.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- kebekeloku.weebly.com
- waxojokizubow.weebly.com
- s3.amazonaws.com
- tisatazufewuvo.weebly.com
- bivitomelonex.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report