SUSPICIOUS — normal_5f87793d8b3ed.pdf
SUSPICIOUS — normal_5f87793d8b3ed.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4b9562105fee82ec7e768383ccf0f68b9faad684ab488e5d75a59d7b11ab8d9b - SHA-1:
06882f11738ffad8edaf85eea6738aefd0a323fa - MD5:
9f5e2fd8c662a9ea2e8a9981fd540763 - ssdeep:
1536:2GFwp6NkCC0FXOwNh6vucIkoYMg7+Ckf:PFwpmzOwNh6FIy+P - TLSH:
T1DB338EF340A7EC8C7B8EAF479EE715A96586D38861239790448C763C807C7FE6E50921 - Submitted as: normal_5f87793d8b3ed.pdf
- File type: pdf · Size: 49526 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=becker+vacuum+pump+vt+4.40+manual, https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/vanojiraxajerubefiza.pdf, https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/a16a30452a4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=becker+vacuum+pump+vt+4.40+manual
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/vanojiraxajerubefiza.pdf
- https://fadusoga.weebly.com/uploads/1/3/0/7/130739873/a16a30452a4.pdf
- https://gazesomudari.weebly.com/uploads/1/3/1/0/131070071/moxere.pdf
- https://site-1042555.mozfiles.com/files/1042555/fidejerojitupijidodobexed.pdf
- https://site-1042348.mozfiles.com/files/1042348/46756060845.pdf
- https://site-1040507.mozfiles.com/files/1040507/suxerifodewemefileredoj.pdf
- https://site-1039617.mozfiles.com/files/1039617/jofodasup.pdf
- https://site-1040399.mozfiles.com/files/1040399/bewomumikenipolojalu.pdf
- https://site-1043569.mozfiles.com/files/1043569/15308765565.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/wogiselaruto-nokage.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/7b8a6b7cb9.pdf
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/viwibutesu.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/dekefomivupe-kovak-talajonipa-fedebiraroz.pdf
- https://site-1048445.mozfiles.com/files/1048445/fimipupogugiwu.pdf
- https://site-1042554.mozfiles.com/files/1042554/49697683582.pdf
- https://site-1037086.mozfiles.com/files/1037086/ginubeka.pdf
- https://site-1036972.mozfiles.com/files/1036972/44058836687.pdf
- https://uploads.strikinglycdn.com/files/c030a9ad-95bc-4d66-bbe6-07423a89291c/78522035845.pdf
- https://uploads.strikinglycdn.com/files/8a11832e-b9e6-489e-aea7-969c9c199915/26720641238.pdf
- https://uploads.strikinglycdn.com/files/9236a951-e350-4b5b-8720-8757b9688df3/89551144206.pdf
- https://uploads.strikinglycdn.com/files/73445cde-738e-40ec-8fab-bf818b5fb93e/82426882353.pdf
- https://uploads.strikinglycdn.com/files/eaee22e1-e3d2-4d80-bd8e-6c512774984e/puzaxaruwoxo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- zoxuzuxebexot.weebly.com
- fadusoga.weebly.com
- gazesomudari.weebly.com
- site-1042555.mozfiles.com
- site-1042348.mozfiles.com
- site-1040507.mozfiles.com
- site-1039617.mozfiles.com
- site-1040399.mozfiles.com
- site-1043569.mozfiles.com
- xojerajap.weebly.com
- jawasolasazilem.weebly.com
- viweposedijul.weebly.com
- medizagokitoni.weebly.com
- site-1048445.mozfiles.com
- site-1042554.mozfiles.com
- site-1037086.mozfiles.com
- site-1036972.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report