SUSPICIOUS — normal_5f8d8ff327cdf.pdf
SUSPICIOUS — normal_5f8d8ff327cdf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
2aa5eba7d7c00ad673e51bc186f253cf84fc8334169414731fdad9567246754c - SHA-1:
1948dce07f0f727b205dc60c4d6309a287b06e41 - MD5:
baafce8b79b8fcbcd68028d7e75fb9c0 - ssdeep:
768:8HgGzpD5pDJLJGMYIxvhdpdPmr1dj8Vu6dysHCXx8gBox1FzUlnjNICiYeBlcQPx:hGFFph2j8V3csHaNk4NRPeBlcQPx - TLSH:
T1F634AEF31057FD4C7A4B6B07EEE601A9A58AC748212797E00488777CD0BC2ED6E16761 - Submitted as: normal_5f8d8ff327cdf.pdf
- File type: pdf · Size: 53775 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=aplikasi+download+lagu+di+youtube+untuk+android, https://uploads.strikinglycdn.com/files/ffa5fb74-dbe1-4eed-a9f9-a77636b750ac/803588276.pdf, https://uploads.strikinglycdn.com/files/d52d6059-a5cd-4af8-8046-b7b67c54c502/kuronokesafugibupe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=aplikasi+download+lagu+di+youtube+untuk+android
- https://uploads.strikinglycdn.com/files/ffa5fb74-dbe1-4eed-a9f9-a77636b750ac/803588276.pdf
- https://uploads.strikinglycdn.com/files/d52d6059-a5cd-4af8-8046-b7b67c54c502/kuronokesafugibupe.pdf
- https://uploads.strikinglycdn.com/files/8257dd96-cb9b-4bb2-9862-17a6c5e6010f/ff15_adult_mods.pdf
- https://uploads.strikinglycdn.com/files/1285ee9a-2bc1-4939-b1cb-8640c9bedf8a/anesthesia_manual_of_surgical_procedures.pdf
- https://uploads.strikinglycdn.com/files/492af93d-4abc-438a-bbf6-5673b124ac2d/mesuwarew.pdf
- https://cdn-cms.f-static.net/uploads/4379961/normal_5f8b74dfd9cc2.pdf
- https://uploads.strikinglycdn.com/files/3d2337e1-b872-4e4b-9d30-9e751330a5fe/savutamuvazumaj.pdf
- https://uploads.strikinglycdn.com/files/1042580a-20bf-4fc3-b556-36b2c904383d/76121699054.pdf
- https://uploads.strikinglycdn.com/files/94df1efc-213b-4339-96a0-aa75ef2480b3/xakagepek.pdf
- https://uploads.strikinglycdn.com/files/13fb1bfc-53ac-4e78-b199-d51c133a4f6b/8913681521.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f877c7f72eea.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f86f6488b22c.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f87506c91a27.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f8817521abc2.pdf
- https://cdn-cms.f-static.net/uploads/4374522/normal_5f8a13c9d49bd.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f89c5171e676.pdf
- https://cdn-cms.f-static.net/uploads/4373502/normal_5f8a722ea82c9.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/loforesebamofikuv.pdf
- https://jimigafekalese.weebly.com/uploads/1/3/1/4/131407537/fomaridamere-jemilelarejasu-vumuletik.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ttraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- zimiduninu.weebly.com
- jimigafekalese.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report