SUSPICIOUS — a_year_with_frog_and_toad_script.pdf
SUSPICIOUS — a_year_with_frog_and_toad_script.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b602e71d9544eb468e713f520e57f4e5c0a141fb398350d4ffc38ab60d1e2a6c - SHA-1:
a814cd2a60184727d8cba7a84d5ff8406663783d - MD5:
4af9c8cd6831c6ce28ae8d689ef05d23 - ssdeep:
768:5gGzpDDpsBKw/O2o597r9WH0RJiyVROrKhbg9vNLNFrg9e7RkQBmo5:6GFPpAZs63yVRsW09vNwA7jBmo5 - TLSH:
T10E327CF350B7EC8C3A8BFB076DB72159A189D289613396A04188772DC4BC6BD7F00A15 - Submitted as: a_year_with_frog_and_toad_script.pdf
- File type: pdf · Size: 43836 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=a+year+with+frog+and+toad+script, https://suganolorifumu.weebly.com/uploads/1/3/0/8/130814011/ebb59aaecd1.pdf, https://legadiduzavof.weebly.com/uploads/1/3/2/6/132681829/zarofabo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=a+year+with+frog+and+toad+script
- https://suganolorifumu.weebly.com/uploads/1/3/0/8/130814011/ebb59aaecd1.pdf
- https://legadiduzavof.weebly.com/uploads/1/3/2/6/132681829/zarofabo.pdf
- https://vodipewelo.weebly.com/uploads/1/3/1/6/131637384/lakox-vilorilebas-tikemoti.pdf
- https://s3.amazonaws.com/jamokaroxoj/98710413167.pdf
- https://s3.amazonaws.com/nefagolom/essential_haematology_7th_edition_download.pdf
- https://s3.amazonaws.com/mafavuzenoliki/87269043245.pdf
- https://s3.amazonaws.com/fasanag/52689710483.pdf
- https://uploads.strikinglycdn.com/files/45595fbc-1585-46d0-ab51-84f480f86626/free_download_ms_office_notes.pdf
- https://uploads.strikinglycdn.com/files/d28186e6-9bd0-4187-bcf6-f49332a7ef98/mazabilerodimivezegokutu.pdf
- https://uploads.strikinglycdn.com/files/61d17614-2ab4-4b5e-94ee-b3bc4089a8d6/64488864005.pdf
- https://uploads.strikinglycdn.com/files/2aee5d8a-6408-47dc-9355-d26a74aaa404/xavinutejugetewajukub.pdf
- https://uploads.strikinglycdn.com/files/f9f9481d-f0d8-401e-a644-ae3dad0cd7dd/32683180276.pdf
- https://uploads.strikinglycdn.com/files/179486ec-3281-4cfe-a1d5-6eaf3e44042a/kabedojisadomuvujotuwa.pdf
- https://uploads.strikinglycdn.com/files/c41b5fcc-5e3e-44e1-b96e-fe785dd5c9c2/73096305410.pdf
- https://uploads.strikinglycdn.com/files/339a40e1-931e-473e-8490-11007e41d02f/54366517689.pdf
- https://cdn-cms.f-static.net/uploads/4370092/normal_5f8b4398f048b.pdf
- https://cdn-cms.f-static.net/uploads/4366047/normal_5f871dd07536b.pdf
- https://cdn-cms.f-static.net/uploads/4383327/normal_5f8fc34631b0c.pdf
- https://cdn-cms.f-static.net/uploads/4387424/normal_5f905eaf64d07.pdf
- https://cdn-cms.f-static.net/uploads/4376358/normal_5f8bbe612178e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- suganolorifumu.weebly.com
- legadiduzavof.weebly.com
- vodipewelo.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report