SUSPICIOUS — normal_5fa8fe29e176a.pdf
SUSPICIOUS — normal_5fa8fe29e176a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4942204b1191e7267bb755d84a4ab267e0e70dd2fb34d2abe5d4111c0a971657 - SHA-1:
81af0f1b385c0c56ca397bf18ce7e2a4ea5c39c8 - MD5:
4d9601796cd9b17f6cf782f3a1f7e8d0 - ssdeep:
768:/gGzpDMjUEhjZ5+sHJrugOnTPg2CT4SGKClsEtttBy/rJnJvoA:IGFAjoYJrzOLgLT4nKwbttDy/VnJvoA - TLSH:
T1C332AEF300A3ED8C7A86AF03AEAB059D1449D74D7026976144DC7B3DC9BC2BD6E20961 - Submitted as: normal_5fa8fe29e176a.pdf
- File type: pdf · Size: 43806 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffnew.ru/123?keyword=dying+light+the+following+guide, https://uploads.strikinglycdn.com/files/79ea43eb-c1f6-448a-8e51-73b1f2432033/3765255696.pdf, https://uploads.strikinglycdn.com/files/7f56ffb2-c42e-4c2d-86c3-a6b5593702ac/davabovexivudifamim.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffnew.ru/123?keyword=dying+light+the+following+guide
- https://uploads.strikinglycdn.com/files/79ea43eb-c1f6-448a-8e51-73b1f2432033/3765255696.pdf
- https://uploads.strikinglycdn.com/files/7f56ffb2-c42e-4c2d-86c3-a6b5593702ac/davabovexivudifamim.pdf
- https://uploads.strikinglycdn.com/files/a2d52a3f-8778-4801-9a19-3883cc292682/vertical_and_horizontal_integration_apush_definition.pdf
- https://uploads.strikinglycdn.com/files/f0441ce8-692e-413a-a5b3-ab70f850d36d/allegiant_book_free_download.pdf
- https://uploads.strikinglycdn.com/files/fd6ee745-d636-405d-be97-24053ddd4850/39975587999.pdf
- https://zijavenokin.weebly.com/uploads/1/3/4/3/134315340/jikijib.pdf
- https://jajipovel.weebly.com/uploads/1/3/4/5/134527293/luvepofaza_nijani_zededo_saderaw.pdf
- https://uploads.strikinglycdn.com/files/bb78801c-9d52-4b97-9040-043ea0c94448/lagogoronikesakigibavis.pdf
- https://uploads.strikinglycdn.com/files/7a9ed7cb-62a1-480e-a4dd-5ed7960ec25f/33462813704.pdf
- https://uploads.strikinglycdn.com/files/7bece32f-4dba-42a1-87cf-70ba6d1deadc/kosoke.pdf
- https://lavigumujow.weebly.com/uploads/1/3/4/4/134438710/muwinexaka.pdf
- https://zenovoruzunej.weebly.com/uploads/1/3/4/3/134339910/xifepagejobetuxovori.pdf
- https://cdn-cms.f-static.net/uploads/4374519/normal_5fa4435936a29.pdf
- https://vezidinudavad.weebly.com/uploads/1/3/4/4/134481570/rivulonipipobuf_temunem_mimidekuv.pdf
- https://cdn-cms.f-static.net/uploads/4370530/normal_5f96470476118.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/delelides_dasexurekiwar_jajumab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffnew.ru
- uploads.strikinglycdn.com
- zijavenokin.weebly.com
- jajipovel.weebly.com
- lavigumujow.weebly.com
- zenovoruzunej.weebly.com
- cdn-cms.f-static.net
- vezidinudavad.weebly.com
- dutitujazekap.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report