SUSPICIOUS — normal_5f91facfacc03.pdf
SUSPICIOUS — normal_5f91facfacc03.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
27e3936281debd2f5c3f5f10a7b0bb0df557a0f9f19ebdebd17bb550bde9c192 - SHA-1:
ff22a78f5adb3844171f5acf604c7341c66ece4e - MD5:
7a4c02a001c9d9bc575e0fba83319b7d - ssdeep:
1536:tGFMplxPzYVxqjBZhg10OOU4I0RCf/co86i:wFMpl6+jBQ10FUr0sfbQ - TLSH:
T192338EF34077ED4C3A8A9B076EFA255E9049EA8C5132A66005847B3DC5BC7BD7F10A60 - Submitted as: normal_5f91facfacc03.pdf
- File type: pdf · Size: 50446 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=translate+pdf+image+from+french+to+english, https://uploads.strikinglycdn.com/files/79db64f8-2032-40cf-9e2d-39c050743b32/62101128834.pdf, https://uploads.strikinglycdn.com/files/b3096c8e-be1e-49ac-a613-b95f81b00a97/lefiferajupigexurowifetar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=translate+pdf+image+from+french+to+english
- https://s3.amazonaws.com/wonoti/45653025297.pdf
- https://s3.amazonaws.com/mavixu/blouse_skirt_pants_style_book.pdf
- https://s3.amazonaws.com/viboxikuz/tanatologia_libros.pdf
- https://s3.amazonaws.com/xovajukoxin/article_in_apa_format.pdf
- https://s3.amazonaws.com/wunupalezozerud/fizesunevuw.pdf
- https://s3.amazonaws.com/henghuili-files2/advanced_neurology_life_support_2017.pdf
- https://s3.amazonaws.com/mijedusovineti/81453980396.pdf
- https://uploads.strikinglycdn.com/files/79db64f8-2032-40cf-9e2d-39c050743b32/62101128834.pdf
- https://uploads.strikinglycdn.com/files/b3096c8e-be1e-49ac-a613-b95f81b00a97/lefiferajupigexurowifetar.pdf
- https://rurevudo.weebly.com/uploads/1/3/4/2/134265418/leretesutefolu_durejozil_nogupuwebe.pdf
- https://rewemekekebaz.weebly.com/uploads/1/3/1/4/131406535/8f9093.pdf
- https://nitetezelimon.weebly.com/uploads/1/3/1/4/131438651/d7998284670f7.pdf
- https://norumevi.weebly.com/uploads/1/3/0/9/130969469/5290993.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/vudodapazepipux_kijemomebegax_velagokotukif.pdf
- https://cdn.shopify.com/s/files/1/0493/0699/2799/files/nouns_and_verbs_worksheet_1st_grade.pdf
- https://cdn.shopify.com/s/files/1/0496/0724/5976/files/97443152341.pdf
- https://cdn.shopify.com/s/files/1/0492/8339/9836/files/24415808978.pdf
- https://cdn.shopify.com/s/files/1/0432/0319/9138/files/belt_conveyor_brochure.pdf
- https://uploads.strikinglycdn.com/files/4237f944-84c8-41c1-8a43-b9ae91b54d25/lefukagilisinijilefazone.pdf
- https://uploads.strikinglycdn.com/files/0980b72b-282a-4521-8f50-e28b301911cf/85005710800.pdf
- https://uploads.strikinglycdn.com/files/05e919db-1955-4f33-bd68-e8282679ee07/91045065690.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- rurevudo.weebly.com
- rewemekekebaz.weebly.com
- nitetezelimon.weebly.com
- norumevi.weebly.com
- vuxozajuje.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report