SUSPICIOUS — normal_5fa811e661e77.pdf
SUSPICIOUS — normal_5fa811e661e77.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7f35d4a20cd69825bb0aa91e9fd8b55bbb7f85c9f71ec4cf50fb43c6ab1427bc - SHA-1:
d2065ad30b35bb814f257c1bdd049c044d4f8a42 - MD5:
ed238dd0d72c0180be1706fe51a6661a - ssdeep:
1536:PGFAmSiwPuwQQplNQMnjBR1TbmDbg5b3mjDjkvIl5O74:+FA+wQQpcYxtb3mj/kvk1 - TLSH:
T1D338D0F3B447ED8C7D89BB03EA7A14A8514EC28C5127D7A06D843B7DC0B86BD2E50961 - Submitted as: normal_5fa811e661e77.pdf
- File type: pdf · Size: 77113 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://traffmen.ru/123?keyword=diamond+touch+pos+software, https://cdn-cms.f-static.net/uploads/4411922/normal_5f9575d91ba49.pdf, https://jelopujepifo.weebly.com/uploads/1/3/4/3/134341958/b94b33eb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffmen.ru/123?keyword=diamond+touch+pos+software
- https://cdn-cms.f-static.net/uploads/4411922/normal_5f9575d91ba49.pdf
- https://jelopujepifo.weebly.com/uploads/1/3/4/3/134341958/b94b33eb.pdf
- https://nizesuvijeva.weebly.com/uploads/1/3/1/6/131607023/f567c.pdf
- https://uploads.strikinglycdn.com/files/a24675a8-d7d2-453b-9e49-462089723d4c/61045951152.pdf
- https://gifimaxenewurup.weebly.com/uploads/1/3/4/4/134458705/0ea6c2284d7c151.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/sonur_fafos.pdf
- https://dikosunasalimob.weebly.com/uploads/1/3/4/3/134363034/pagogu-nanuxejakim.pdf
- https://jinugavov.weebly.com/uploads/1/3/4/4/134438703/28cac2f6f2937.pdf
- https://uploads.strikinglycdn.com/files/6d43056b-d372-4fd3-a82f-78d7fcd7408c/935_dispatch_wordpress.pdf
- https://nikuwexipamojag.weebly.com/uploads/1/3/0/8/130813731/mivawarezin_pemupib_bimugozutudufib_kadesode.pdf
- https://uploads.strikinglycdn.com/files/25145e08-bc9b-4362-be48-45f03c2addb3/29473583486.pdf
- https://uploads.strikinglycdn.com/files/0587ae5b-6f81-4ebd-afec-0642b8d5d9ca/leloxojumumaxonekizowo.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/cc4139.pdf
- http://www.diamondtou
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffmen.ru
- cdn-cms.f-static.net
- jelopujepifo.weebly.com
- nizesuvijeva.weebly.com
- uploads.strikinglycdn.com
- gifimaxenewurup.weebly.com
- xawuwotogot.weebly.com
- dikosunasalimob.weebly.com
- jinugavov.weebly.com
- nikuwexipamojag.weebly.com
- besiwalufeg.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.diamondtou
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report