SUSPICIOUS — normal_5f95fb87cd0cf.pdf
SUSPICIOUS — normal_5f95fb87cd0cf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4ada2dc819f82b3e1e95cf72410b55902dd8da5a98f7523bca0aa3925965b184 - SHA-1:
9a7a70abb8ad39cb98be1950fd2a2483159f9874 - MD5:
af004e516fea23a280d2109c3940b68b - ssdeep:
1536:kGFppN70uFGcebp5AUxkmNQliX0vWZSJnXEM5:xFpp50uFmHVbQ7c6nX7 - TLSH:
T16A349EF310A7DC4C7A8EAB076EEB116DA18AD74D6133AB501488762CC5FCAFE5E00651 - Submitted as: normal_5f95fb87cd0cf.pdf
- File type: pdf · Size: 53437 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=fairy+bread+procedure+worksheet, https://cdn-cms.f-static.net/uploads/4412160/normal_5f948346e963c.pdf, https://cdn-cms.f-static.net/uploads/4376105/normal_5f91729e61a9f.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=fairy+bread+procedure+worksheet
- https://cdn-cms.f-static.net/uploads/4412160/normal_5f948346e963c.pdf
- https://cdn-cms.f-static.net/uploads/4376105/normal_5f91729e61a9f.pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f889efb91dff.pdf
- https://cdn-cms.f-static.net/uploads/4368982/normal_5f8ad381b587e.pdf
- https://cdn-cms.f-static.net/uploads/4380545/normal_5f90d3b2419b3.pdf
- https://cdn-cms.f-static.net/uploads/4383915/normal_5f8c08908babc.pdf
- https://cdn-cms.f-static.net/uploads/4377938/normal_5f8ab97a6b6f6.pdf
- https://s3.amazonaws.com/towakog/enlace_metalico_y_elementos_semiconductores.pdf
- https://s3.amazonaws.com/domegagowevag/volunola.pdf
- https://s3.amazonaws.com/gupawupigawono/91387245671.pdf
- https://s3.amazonaws.com/jamokaroxoj/sequence_and_series_bsc.pdf
- https://uploads.strikinglycdn.com/files/037fa864-d60f-4c85-9764-858120c8f7cf/11784453067.pdf
- https://uploads.strikinglycdn.com/files/eabb0c9c-ca6f-497c-b42a-225e2cb7da77/vavonufirigaxaxazegiruj.pdf
- https://uploads.strikinglycdn.com/files/3bd9e161-723f-4710-8b81-4fee045f872e/girasajunasufaburewubet.pdf
- https://uploads.strikinglycdn.com/files/917baf3d-4009-4397-8c7c-cab3e1573273/tulemaxanutorulo.pdf
- https://uploads.strikinglycdn.com/files/42ecfd73-c3e2-4eed-9b4d-abd7eed2777f/xoxawaxitijilapodixuki.pdf
- https://dekekutema.weebly.com/uploads/1/3/4/4/134440935/6659646.pdf
- https://jovikuveditowe.weebly.com/uploads/1/3/0/8/130874612/sujolosi.pdf
- https://keruzexutebimoz.weebly.com/uploads/1/3/4/3/134310977/voxovajufibimamu.pdf
- https://firedisivimi.weebly.com/uploads/1/3/0/9/130969818/temezug-pogudajuwo.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/6f984.pdf
- https://uploads.strikinglycdn.com/files/915c2673-4240-4349-a15f-83fe6e192299/45952080091.pdf
- https://uploads.strikinglycdn.com/files/253372ec-4674-4209-9aa6-8ff21655a479/xitolapa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- dekekutema.weebly.com
- jovikuveditowe.weebly.com
- keruzexutebimoz.weebly.com
- firedisivimi.weebly.com
- vilukenuxe.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report