SUSPICIOUS — normal_5f93d50ba2447.pdf
SUSPICIOUS — normal_5f93d50ba2447.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8840b9550b68fc20b539672adfa87691f54a7cfcb9f11c1af47c5369eda3a5d9 - SHA-1:
c3b24e60d5d9bd797ab10157a84f5a2661c45617 - MD5:
8a960460c956aceccb5317403cac3303 - ssdeep:
768:BgGzpD+Uan/g5DygHdw1gbsCB1ZbrLAkxiiz2Jlo3F5Q8IBtw4uvqWh9f/0CVWwJ:yGFaXd8x7qJlo/PIBtwtvqWhh0gX46H - TLSH:
T192338EF36197EC8C3A86AB1799B70469758BC78C61339F5014987B2CC07CABD7E10A51 - Submitted as: normal_5f93d50ba2447.pdf
- File type: pdf · Size: 47844 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/123?keyword=aov+indonesia+server+apk, https://uploads.strikinglycdn.com/files/cf5c57ab-7747-42f9-8f4a-7cd64f034b1f/89671214693.pdf, https://uploads.strikinglycdn.com/files/07b3c8b0-1048-460e-9bd0-444a2f2fc8b5/xuxotazavesa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=aov+indonesia+server+apk
- https://uploads.strikinglycdn.com/files/cf5c57ab-7747-42f9-8f4a-7cd64f034b1f/89671214693.pdf
- https://uploads.strikinglycdn.com/files/07b3c8b0-1048-460e-9bd0-444a2f2fc8b5/xuxotazavesa.pdf
- https://uploads.strikinglycdn.com/files/af639a23-3632-4ed8-9636-4a070cb4efae/circuits_for_dummies.pdf
- https://cdn-cms.f-static.net/uploads/4384628/normal_5f8c4efcae5b3.pdf
- https://cdn-cms.f-static.net/uploads/4393353/normal_5f90ff5c31f72.pdf
- https://cdn-cms.f-static.net/uploads/4373526/normal_5f8c0f7c50344.pdf
- https://cdn-cms.f-static.net/uploads/4394073/normal_5f90bb04d508f.pdf
- https://cdn-cms.f-static.net/uploads/4405179/normal_5f930a6901e5f.pdf
- https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/xitipobopi-ruwug-pozovu.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/davejibot_befil_fanevupolur_vijawu.pdf
- https://s3.amazonaws.com/sesafefanulokam/introduction_to_geometrical_construction.pdf
- https://s3.amazonaws.com/rizezobabub/embryogenesis_stages.pdf
- https://s3.amazonaws.com/fasanag/sedaxozoberorideges.pdf
- https://s3.amazonaws.com/saziwijaxodav/89591579643.pdf
- https://cdn-cms.f-static.net/uploads/4408707/normal_5f93b3e4b2ce3.pdf
- https://cdn-cms.f-static.net/uploads/4377388/normal_5f8f5d4a363da.pdf
- https://cdn-cms.f-static.net/uploads/4381547/normal_5f8e0519ea98c.pdf
- http://aov.co.idCS
- https://support.garena.co.id/homeFacebook
- https://www.facebook.co
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ttraff.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- moxitasa.weebly.com
- jakedekokobara.weebly.com
- s3.amazonaws.com
- www.facebook.co
- www.w3.org
- purl.org
- ns.adobe.com
- aov.co.idcs
- support.garena.co.id
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report