SUSPICIOUS — normal_5fa673339b473.pdf
SUSPICIOUS — normal_5fa673339b473.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
d47695970ebd4e356aafce175dd6329da8bdd797dea4bf942ad1bb32bd3f7c6b - SHA-1:
034c6f8434c1203c2cb23568d0d341ece31ebc4d - MD5:
51a4e1cb2052eaf007a0707fb15308a8 - ssdeep:
768:MgGzpDrSHOZ9SkvJ8jn1eQwwmqkhDia5SHLYg1IWvUgCm:JGFPxZdvyjn1pYgO7gCm - TLSH:
T110329EF351A7ED4C3A8BAB135ABA15986089D7482023A7B04C8C777DC0BC7BD3E40961 - Submitted as: normal_5fa673339b473.pdf
- File type: pdf · Size: 45669 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafficel.ru/123?keyword=booker+t+and+web+poem, https://sizojupitad.weebly.com/uploads/1/3/4/3/134332657/jofavobel_nitogib.pdf, https://uploads.strikinglycdn.com/files/3fbd2b23-d7a4-484b-8f60-3d8838a1df30/gaxefevajejegudade.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/123?keyword=booker+t+and+web+poem
- https://sizojupitad.weebly.com/uploads/1/3/4/3/134332657/jofavobel_nitogib.pdf
- https://uploads.strikinglycdn.com/files/3fbd2b23-d7a4-484b-8f60-3d8838a1df30/gaxefevajejegudade.pdf
- https://uploads.strikinglycdn.com/files/22286c57-5a47-45c1-b360-7204ca29697b/kejidazufusizijesip.pdf
- https://uploads.strikinglycdn.com/files/4b2ba3a4-2baa-40d6-bef5-d390dfef0059/33363606690.pdf
- https://s3.amazonaws.com/nisoxow/fubaz.pdf
- https://uploads.strikinglycdn.com/files/67a13188-0f85-4fba-af1b-c0736275d2a5/russian_alphabet_song_animals.pdf
- https://jidugurulepapol.weebly.com/uploads/1/3/4/3/134310086/ca6dd3.pdf
- https://kolivobaka.weebly.com/uploads/1/3/4/5/134500933/feruxedixarigi.pdf
- https://cdn-cms.f-static.net/uploads/4378613/normal_5f8d6fa2e338b.pdf
- https://nonikezit.weebly.com/uploads/1/3/4/3/134335915/nomozesesebuxu.pdf
- https://uploads.strikinglycdn.com/files/1828ccec-5a10-4198-b021-b3e0ad896feb/52279460690.pdf
- https://cdn-cms.f-static.net/uploads/4384632/normal_5f91dffe6b903.pdf
- https://s3.amazonaws.com/novifamigot/74307093032.pdf
- https://uploads.strikinglycdn.com/files/27a90e74-2bda-4467-9d8f-d5b6fe889093/suzexovaw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- sizojupitad.weebly.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- jidugurulepapol.weebly.com
- kolivobaka.weebly.com
- cdn-cms.f-static.net
- nonikezit.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report