SUSPICIOUS — normal_5f9347a1e5aae.pdf
SUSPICIOUS — normal_5f9347a1e5aae.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b48674831032e37c01f9777a8d759f70eadacfa3602b919b165d88985a7cb2ee - SHA-1:
867e71b447ba360e4b9cb7233d0ec7d7226caed7 - MD5:
3763546b8b7296371c056ef388994c34 - ssdeep:
768:iJgGzpD1+Yq+GcSXWsXml7ZBptCUkLgzQCxpSMIlrEHqj1FZbFW3maUWh:5GFZ+P+0xQzptyLgzQ2VIlwKj1M3maUo - TLSH:
T1A632AEF710A7DC4C7AC6EB1359AB249DA289D6886032D7644489B36CC4BC7BD7E01A70 - Submitted as: normal_5f9347a1e5aae.pdf
- File type: pdf · Size: 44828 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=android+version+for+samsung+galaxy+s6, https://uploads.strikinglycdn.com/files/6708efe3-0dd2-4e90-bcfe-7d7985aafb66/fejijuliverokubiludin.pdf, https://uploads.strikinglycdn.com/files/8a015f29-1c68-4731-9bd0-1dde43627007/40583046742.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/123?keyword=android+version+for+samsung+galaxy+s6
- https://uploads.strikinglycdn.com/files/6708efe3-0dd2-4e90-bcfe-7d7985aafb66/fejijuliverokubiludin.pdf
- https://uploads.strikinglycdn.com/files/8a015f29-1c68-4731-9bd0-1dde43627007/40583046742.pdf
- https://uploads.strikinglycdn.com/files/0c3e048b-e923-421b-a0c8-074846cd97cd/manual_recycling_baler.pdf
- https://tabuxeniki.weebly.com/uploads/1/3/2/6/132682737/bc162df109b50.pdf
- https://molisemopum.weebly.com/uploads/1/3/1/4/131437834/bamunaw.pdf
- https://s3.amazonaws.com/sugaguxagu/60866709811.pdf
- https://s3.amazonaws.com/fasanag/74574206506.pdf
- https://lefedatit.weebly.com/uploads/1/3/0/7/130776734/lejif.pdf
- https://xigokerurubupa.weebly.com/uploads/1/3/4/3/134312623/9374139.pdf
- https://tisatazufewuvo.weebly.com/uploads/1/3/1/1/131163687/relax-fosimok-zevupurow.pdf
- https://nitetezelimon.weebly.com/uploads/1/3/1/4/131438651/658902.pdf
- https://bajusumuke.weebly.com/uploads/1/3/2/7/132741128/ac1ec53d6.pdf
- https://porelananov.weebly.com/uploads/1/3/0/7/130775759/bulibufusutenem.pdf
- https://nibobesexetew.weebly.com/uploads/1/3/4/2/134266191/dodukaxilejavudeta.pdf
- https://s3.amazonaws.com/susopuzupure/wogawutanabipimi.pdf
- https://s3.amazonaws.com/sezebepit/18833945353.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- tabuxeniki.weebly.com
- molisemopum.weebly.com
- s3.amazonaws.com
- lefedatit.weebly.com
- xigokerurubupa.weebly.com
- tisatazufewuvo.weebly.com
- nitetezelimon.weebly.com
- bajusumuke.weebly.com
- porelananov.weebly.com
- nibobesexetew.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report