SUSPICIOUS — normal_5f895c71e7339.pdf
SUSPICIOUS — normal_5f895c71e7339.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
6bb835e364b9b85879a89814fdd532a13d2560e9708a7e657ecd1a57a0afba28 - SHA-1:
48b17ca6ac04112d0648fcb4c6a961022463b5ee - MD5:
3413757440f70d0c1579da2339f344bc - ssdeep:
768:FgGzpDCpAL3zHs3Sk47lpLl/ZzS7dhNgYHp0VTADRwMhC81118Dv/Oh4FirKjRgQ:WGFepQXlpLl/hS732YJ0tADyMf1118DL - TLSH:
T1FA33AFF354A7EC5D7A866B0368A6141D2489D78CB23BE36050CC7A2DC1BC6BDBF50960 - Submitted as: normal_5f895c71e7339.pdf
- File type: pdf · Size: 48588 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=bates+numbering+pdf+pro, https://nubojubixuxo.weebly.com/uploads/1/3/1/4/131410311/golikotematazerir.pdf, https://vuxilimibipemop.weebly.com/uploads/1/3/1/4/131453056/4fe5684cf11.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=bates+numbering+pdf+pro
- https://nubojubixuxo.weebly.com/uploads/1/3/1/4/131410311/golikotematazerir.pdf
- https://vuxilimibipemop.weebly.com/uploads/1/3/1/4/131453056/4fe5684cf11.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/3157557.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/busixakowun_zefisuni.pdf
- https://gemenudotipetal.weebly.com/uploads/1/3/2/6/132695720/lopaxarusiw.pdf
- https://cdn.shopify.com/s/files/1/0434/3562/2552/files/what_is_a_nickelodeon_jukebox.pdf
- https://cdn.shopify.com/s/files/1/0476/9126/8262/files/9077255766.pdf
- https://uploads.strikinglycdn.com/files/ef89fce0-70c8-4fc5-b9ce-52eddd8680a3/93472331419.pdf
- https://uploads.strikinglycdn.com/files/02229f4b-2720-449c-a37c-7faf7e3e66f2/wawivafox.pdf
- https://uploads.strikinglycdn.com/files/cad5c68c-c289-4703-8dba-d381279d5c32/18912310956.pdf
- https://cdn.shopify.com/s/files/1/0500/9122/9349/files/96229820937.pdf
- https://cdn.shopify.com/s/files/1/0440/8007/0821/files/47241215415.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/lixokit.pdf
- https://turomanusogagi.weebly.com/uploads/1/3/1/4/131453559/wuxunefipirov.pdf
- https://uploads.strikinglycdn.com/files/0b20cea5-5e41-41fa-9cdd-93f4176c1d41/38092834280.pdf
- https://uploads.strikinglycdn.com/files/b21c8b00-48de-41a0-8f0c-94f54737d56d/febudenowopimibonod.pdf
- https://uploads.strikinglycdn.com/files/1a5c702b-81ca-4244-931a-0789db189b71/katijegajadizolenogudebi.pdf
- https://uploads.strikinglycdn.com/files/912048ab-6069-4e3a-bfbd-c231d4b24735/98831055227.pdf
- https://uploads.strikinglycdn.com/files/eeb2f880-37db-4dd8-8514-493fa8f4c972/ribolabovi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- nubojubixuxo.weebly.com
- vuxilimibipemop.weebly.com
- bedizegoresupa.weebly.com
- jakedekokobara.weebly.com
- gemenudotipetal.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- zoveponezewuda.weebly.com
- turomanusogagi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report