SUSPICIOUS — normal_5fa84ed1654a2.pdf
SUSPICIOUS — normal_5fa84ed1654a2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8dd977b51b9fbf3fe973a3f87a2741e7fc91a81daad3826710274cb67a709a13 - SHA-1:
b7c9c046c4096a865ad069d2d82f6804a0c20cc4 - MD5:
7e7cf6d23e3561e9f2e9d62e032ed76b - ssdeep:
768:bgGzpDslN3vOXD/xHi4YpRWim4+/SMpam55qJ+5AAoeTioVg6Pj6aCR+nN:kGF4laxC4YHj+5pj55wAoe+T6jLCR+nN - TLSH:
T14D32AEF350A3DC8C3A86AF032D76146E6445C78DB133A67415D87A2CD4B86BD6F00972 - Submitted as: normal_5fa84ed1654a2.pdf
- File type: pdf · Size: 43282 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafficel.ru/123?keyword=six+mile+water+caravan+park, https://zidinekolinom.weebly.com/uploads/1/3/4/5/134516346/63a43b8165.pdf, https://bedakowunuva.weebly.com/uploads/1/3/4/3/134342711/d17d5b2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: additional-actions, uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/123?keyword=six+mile+water+caravan+park
- https://zidinekolinom.weebly.com/uploads/1/3/4/5/134516346/63a43b8165.pdf
- https://bedakowunuva.weebly.com/uploads/1/3/4/3/134342711/d17d5b2.pdf
- https://ruxibero.weebly.com/uploads/1/3/4/4/134403554/tosil-fuwululixelisad.pdf
- https://uploads.strikinglycdn.com/files/cedc2c26-c4b4-48a5-a1fd-ea14e5bf7cf4/7048883931.pdf
- https://kojopog.files.wordpress.com/2020/11/download_mockingjay_part_2_free.pdf
- https://cdn-cms.f-static.net/uploads/4387033/normal_5f8d68de40475.pdf
- https://dogiwubof.weebly.com/uploads/1/3/4/4/134400908/2b2ff20.pdf
- https://mudupetem.files.wordpress.com/2020/11/20042446963.pdf
- https://rulomegujenuguv.weebly.com/uploads/1/3/4/3/134329868/bozawevora.pdf
- https://uploads.strikinglycdn.com/files/ff2edbb4-b230-4275-825a-df11f77e35d6/stock_transfer_ledger_template_word.pdf
- https://zatejoru847961968.files.wordpress.com/2020/11/72489844693.pdf
- https://gupoxojuk.files.wordpress.com/2020/11/70600569475.pdf
- https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/357a0f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- zidinekolinom.weebly.com
- bedakowunuva.weebly.com
- ruxibero.weebly.com
- uploads.strikinglycdn.com
- kojopog.files.wordpress.com
- cdn-cms.f-static.net
- dogiwubof.weebly.com
- mudupetem.files.wordpress.com
- rulomegujenuguv.weebly.com
- zatejoru847961968.files.wordpress.com
- gupoxojuk.files.wordpress.com
- mefemanodi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report