SUSPICIOUS — normal_5f87a23002c47.pdf
SUSPICIOUS — normal_5f87a23002c47.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
a52d2414d22065eb2d9aea8695845949c449bee942bdb7288dd1aceee70a6315 - SHA-1:
71062fb1b64e6a279b46d1aac9d144f8c4915212 - MD5:
03f872c948d19358adedf53a95f67e9a - ssdeep:
768:AgGzpDQpFe/vQuL9RtWX9itWnbowReIUhtPEKeojm5qAlTwj:NGF8pFiIXoeUhtPpQlTwj - TLSH:
T1D8326BF35097ED4C7A839B035DEE295DA24AD74C6132E7A0809CAB2CC57C7BD2E51910 - Submitted as: normal_5f87a23002c47.pdf
- File type: pdf · Size: 44092 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=gundam+unicorn+pg+manual, https://site-1037893.mozfiles.com/files/1037893/51384573967.pdf, https://site-1038790.mozfiles.com/files/1038790/fosibadozukawifibimanekub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=gundam+unicorn+pg+manual
- https://site-1037893.mozfiles.com/files/1037893/51384573967.pdf
- https://site-1038790.mozfiles.com/files/1038790/fosibadozukawifibimanekub.pdf
- https://site-1040876.mozfiles.com/files/1040876/vasalebadumujalojusunepif.pdf
- https://site-1041865.mozfiles.com/files/1041865/joganakozefaxenuz.pdf
- https://site-1037121.mozfiles.com/files/1037121/57210821585.pdf
- https://xuvakaxatal.weebly.com/uploads/1/3/1/0/131070170/potakote.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/4041939.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/tikupobef.pdf
- https://pejopazuzaguwoz.weebly.com/uploads/1/3/2/8/132815183/9201798.pdf
- https://cdn-cms.f-static.net/uploads/4366639/normal_5f87278f8b3f2.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f8773a3b99e8.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f8755f41eeda.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f8731a1b9454.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f876f3eb1631.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/2122744.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/77429035c.pdf
- https://uploads.strikinglycdn.com/files/7511476c-60a5-4a01-b85b-09d40a1b1f01/tomoguzi.pdf
- https://uploads.strikinglycdn.com/files/edf37b59-5c63-4063-9fe9-533c35bb7a9d/30266047457.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f870a77cedca.pdf
- https://cdn-cms.f-static.net/uploads/4368474/normal_5f877b8c6705a.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f87365db08a9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- site-1037893.mozfiles.com
- site-1038790.mozfiles.com
- site-1040876.mozfiles.com
- site-1041865.mozfiles.com
- site-1037121.mozfiles.com
- xuvakaxatal.weebly.com
- bedizegoresupa.weebly.com
- viweposedijul.weebly.com
- pejopazuzaguwoz.weebly.com
- cdn-cms.f-static.net
- xojerajap.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report