SUSPICIOUS — normal_5f8f295e79900.pdf
SUSPICIOUS — normal_5f8f295e79900.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
79c3b75cda5b7c165d8f8a2d038a77eeda692a526f07a18ed43e15ef048b586c - SHA-1:
5d1e0ca564a5569e11bbbc30c2299bf18e942858 - MD5:
aef475528d748b7a2d4f2f07eacb0230 - ssdeep:
768:OgGzpDrp6oZ27juntzOohcmu24qdtbWXcjnroyOx0m/lnZiP:rGFvp6WFd8XcjroJ0mVZiP - TLSH:
T1AA316BF31097EC8C7A8B6F03ADEB106A508AD7892136E370558C772CC96C7ED6E14661 - Submitted as: normal_5f8f295e79900.pdf
- File type: pdf · Size: 42042 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=toyota+service+manual+rav4, https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/nukunuraki.pdf, https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/fekijuwadurotozubiso.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=toyota+service+manual+rav4
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/nukunuraki.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/fekijuwadurotozubiso.pdf
- https://jimagofer.weebly.com/uploads/1/3/0/8/130813953/b157112afd08a.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/mojuduliwefagud.pdf
- https://tamagokevalagir.weebly.com/uploads/1/3/0/7/130776783/c2b137b27.pdf
- https://s3.amazonaws.com/leguvefu/darimavibotasorokadodufez.pdf
- https://s3.amazonaws.com/felasorarabipis/fujobutepeb.pdf
- https://cdn-cms.f-static.net/uploads/4367961/normal_5f87555169527.pdf
- https://cdn-cms.f-static.net/uploads/4375704/normal_5f89b29cb0784.pdf
- https://cdn-cms.f-static.net/uploads/4376609/normal_5f8aab72b883a.pdf
- https://cdn.shopify.com/s/files/1/0493/6997/2902/files/79214997865.pdf
- https://cdn.shopify.com/s/files/1/0488/4080/2469/files/fafegerobuzolepif.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/3883418899.pdf
- https://cdn.shopify.com/s/files/1/0495/9889/0147/files/miramar_college_class_schedule_fall_2019.pdf
- https://cdn.shopify.com/s/files/1/0439/2094/9403/files/palubu.pdf
- https://cdn.shopify.com/s/files/1/0437/0799/0184/files/falubisutofigewaji.pdf
- https://cdn.shopify.com/s/files/1/0501/1449/4614/files/tazosipopowuguwisivudif.pdf
- https://cdn.shopify.com/s/files/1/0483/6510/9397/files/letter_of_recommendation_for_nurse_practitioner_program.pdf
- https://cdn.shopify.com/s/files/1/0266/9510/6741/files/90188446705.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- guwomenod.weebly.com
- saxibodusazo.weebly.com
- jimagofer.weebly.com
- dejolezeg.weebly.com
- tamagokevalagir.weebly.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report