SUSPICIOUS — normal_5fa8def1504de.pdf
SUSPICIOUS — normal_5fa8def1504de.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
31775d438d2964cc4023e19fcf8787fff230156e09a14d63f37472e7d593d058 - SHA-1:
de5dbbb71c76e05275e9b1eb0dc32b22106a8168 - MD5:
b48c0ed02cf1427f94f4c19b10e95c63 - ssdeep:
768:mgGzpDpNBVZhtkeBvUNg1BPSXxwr9DmulC3LCVWdTmZ:zGFdPkP6vqQ9DmRLgOTmZ - TLSH:
T11432AEF36093DDCC7AC76B03B9A2105D6547C28D2032DAA01889777CC87CAEDBE159A1 - Submitted as: normal_5fa8def1504de.pdf
- File type: pdf · Size: 45140 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffking.ru/123?keyword=prince+harry+sister+secret, https://rikisuluwujufa.weebly.com/uploads/1/3/1/4/131452938/9433283.pdf, https://cdn-cms.f-static.net/uploads/4416504/normal_5f996eb1961cd.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/123?keyword=prince+harry+sister+secret
- https://rikisuluwujufa.weebly.com/uploads/1/3/1/4/131452938/9433283.pdf
- https://cdn-cms.f-static.net/uploads/4416504/normal_5f996eb1961cd.pdf
- https://uploads.strikinglycdn.com/files/94dd958a-3768-4c0c-ad2b-65e2ad2d001e/38238443449.pdf
- https://uploads.strikinglycdn.com/files/136b8eca-3ff8-46d4-9f56-62c303f3d559/fexixuvosiwerud.pdf
- https://rajomiluti.weebly.com/uploads/1/3/2/6/132682989/b60602f9.pdf
- https://cdn-cms.f-static.net/uploads/4401989/normal_5f91e0bb616ea.pdf
- https://uploads.strikinglycdn.com/files/37acacd5-8fcb-4d48-b3c8-05d944aad4df/chemical_reactor_analysis_and_design.pdf
- https://uploads.strikinglycdn.com/files/cfcc363e-f306-48e3-a4f4-99d32b79301c/the_sleuth_kit_commands.pdf
- https://uploads.strikinglycdn.com/files/183f2cd3-6c1c-49b9-a7d3-768c758957b1/lasukefefi.pdf
- https://uploads.strikinglycdn.com/files/567746dd-e99c-404f-b8a4-e0a122e5bcd1/wajimujetedoni.pdf
- https://uploads.strikinglycdn.com/files/eb952ccc-1f69-40a5-9b0a-4fbbd28eecc1/85912287948.pdf
- https://s3.amazonaws.com/pazifetanegapu/arnold_schwarzenegger_bodybuilding_encyclopedia_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- rikisuluwujufa.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- rajomiluti.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report