SUSPICIOUS — normal_5f87053d62b3e.pdf
SUSPICIOUS — normal_5f87053d62b3e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
496be89c69740c84163304334ed64095069a568ca15a995aae50118ddb0c0b74 - SHA-1:
f4d93071ec59c5ab78623562cbecf884a2137725 - MD5:
0f9689ebd53421fe3f73d33bdcc33eec - ssdeep:
768:egGzpD0p71FbSa9PlzJyH6/cSibAe+lnQyQTPpwnnX3nICWUu:bGFAp71FbXt05bAzlnjQTPpwX3nICWUu - TLSH:
T171327DF340A7EC4C7A876B136DAA259DA089D78CA132E76444C8773CC4BC6FE6E50950 - Submitted as: normal_5f87053d62b3e.pdf
- File type: pdf · Size: 46630 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=printable+worksheets+for+5-6+year+olds, https://uploads.strikinglycdn.com/files/e33bbbd7-6831-49fe-b088-4039ae3790d0/losujibixugukag.pdf, https://uploads.strikinglycdn.com/files/8dc0c6e6-a1cd-4e00-ba8b-842dac74e5e3/73380642952.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=printable+worksheets+for+5-6+year+olds
- https://uploads.strikinglycdn.com/files/e33bbbd7-6831-49fe-b088-4039ae3790d0/losujibixugukag.pdf
- https://uploads.strikinglycdn.com/files/8dc0c6e6-a1cd-4e00-ba8b-842dac74e5e3/73380642952.pdf
- https://uploads.strikinglycdn.com/files/cc1d2864-b34f-4468-a9a1-ccfb294635f5/76593367262.pdf
- https://uploads.strikinglycdn.com/files/380154ee-5aa8-4a22-a6d3-0e7ee2d39426/kajeroninuvo.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/xenemavurinap_jokepirewiteda_fijalezej_gemewije.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kirorafagosox.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/debizikirapanas.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/32e063a95e.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/1000608.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/3373854.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f8702eb03638.pdf
- https://cdn-cms.f-static.net/uploads/4366027/normal_5f86f97fec65f.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f86fb36e07ab.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f86f5658c3ca.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f8704dca56dc.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/d96ddb407408.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/jixidused.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/dozafawegikuxoto.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/dbbd04.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/rebodi.pdf
- https://uploads.strikinglycdn.com/files/6363af1c-228f-4ee3-834e-1b81e50d1cde/gagedusuza.pdf
- https://uploads.strikinglycdn.com/files/44f8d30b-ae8a-4052-970c-d63473996691/gavolotanifopu.pdf
- https://uploads.strikinglycdn.com/files/b4dde618-6e80-4439-9c30-ec4eaa29c9e3/naves.pdf
- https://uploads.strikinglycdn.com/files/05b9bcfc-9aa4-4267-86e2-64c2d5c8b6c4/44451651359.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- vuxozajuje.weebly.com
- gimejexoxixaza.weebly.com
- keniwuki.weebly.com
- fodezamu.weebly.com
- xojerajap.weebly.com
- cdn-cms.f-static.net
- jatorogerujew.weebly.com
- bedizegoresupa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report