SUSPICIOUS — normal_5f94e9b168d29.pdf
SUSPICIOUS — normal_5f94e9b168d29.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
77b0d46e8980d815ec4aa8d01e2b91fd5bcd1e4eb593384e45c2e88d483ef28f - SHA-1:
65eafd799ef26404b2398459a6d08b0e66c915ac - MD5:
8e6bcac0a1544fa52519d572b44ab622 - ssdeep:
768:igGzpDHfODLfhk9kM36MtG2xXIbQhqhWXOTGu0xh8yC9gyMXvjj9L2uizu2X:/GFz+Ta7/UjL0H8f9tM/jJL2uizu2X - TLSH:
T10533A0F35097EC8C7B8B6B136D6B15AD204AD789A12397A000C8772CD47C7EE7E01625 - Submitted as: normal_5f94e9b168d29.pdf
- File type: pdf · Size: 50299 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=cisco+jabber+user+guide+10.6, https://zigegawemofeza.weebly.com/uploads/1/3/1/4/131406932/5132354.pdf, https://risidetumul.weebly.com/uploads/1/3/4/3/134320066/tutixejo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=cisco+jabber+user+guide+10.6
- https://s3.amazonaws.com/pazifetanegapu/69051661431.pdf
- https://s3.amazonaws.com/bizamesuwepe/jesuitas_en_mexico.pdf
- https://s3.amazonaws.com/vavebufevodutob/john_grisham_camino_island.pdf
- https://s3.amazonaws.com/mejawiwomak/online_hotel_reservation_system_thesis.pdf
- https://zigegawemofeza.weebly.com/uploads/1/3/1/4/131406932/5132354.pdf
- https://risidetumul.weebly.com/uploads/1/3/4/3/134320066/tutixejo.pdf
- https://xavujome.weebly.com/uploads/1/3/0/7/130739328/jumugefevi.pdf
- https://bafovulik.weebly.com/uploads/1/3/1/0/131070506/rurubewe.pdf
- https://wosezobar.weebly.com/uploads/1/3/1/8/131856012/bonufag-zusuravufi-zepogadus-komujawosulunu.pdf
- https://cdn-cms.f-static.net/uploads/4366952/normal_5f8af67f72b31.pdf
- https://cdn-cms.f-static.net/uploads/4370268/normal_5f914dd9c1cf6.pdf
- https://cdn-cms.f-static.net/uploads/4367007/normal_5f898e0c4585e.pdf
- https://cdn-cms.f-static.net/uploads/4381081/normal_5f8e8d74d63f2.pdf
- https://cdn-cms.f-static.net/uploads/4394077/normal_5f912aad5b054.pdf
- https://cdn-cms.f-static.net/uploads/4382773/normal_5f907eb7c36ae.pdf
- https://cdn-cms.f-static.net/uploads/4371269/normal_5f94d8aa65833.pdf
- https://cdn-cms.f-static.net/uploads/4372719/normal_5f8a060242930.pdf
- https://cdn-cms.f-static.net/uploads/4374835/normal_5f8b7c2f0448f.pdf
- https://cdn-cms.f-static.net/uploads/4366620/normal_5f94dac8d08f1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ttraff.me
- s3.amazonaws.com
- zigegawemofeza.weebly.com
- risidetumul.weebly.com
- xavujome.weebly.com
- bafovulik.weebly.com
- wosezobar.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report