SUSPICIOUS — normal_5f889f912a2ad.pdf
SUSPICIOUS — normal_5f889f912a2ad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
df91b0660fa9ecb5db69054fce3287451f422222a1c639634ddf5528068c8f21 - SHA-1:
81124ce3e51b72175ceb26a0203f44ab7680f176 - MD5:
243d890b87bed86319d78de8d1d2ceda - ssdeep:
1536:2GF1p2qE4PUTAcm0W6bkxLPD/OwodpCa4tHfaJ:PF1p2uMPm/KkZDmTCa4Rk - TLSH:
T17A35AEF76067ED4CBACF6F179AE71119618AC78C603697904488A73CD4BC6ED3E00A25 - Submitted as: normal_5f889f912a2ad.pdf
- File type: pdf · Size: 62379 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=amazon+web+services+pdf+free+download, https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/9653445.pdf, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/197d80c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=amazon+web+services+pdf+free+download
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/9653445.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/197d80c.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/fubisi.pdf
- https://xonimitofowe.weebly.com/uploads/1/3/2/6/132682232/4380478.pdf
- https://pepuzategazeg.weebly.com/uploads/1/3/1/4/131453576/782682.pdf
- https://site-1036646.mozfiles.com/files/1036646/luzovaxokifan.pdf
- https://site-1043160.mozfiles.com/files/1043160/49251514395.pdf
- https://site-1042633.mozfiles.com/files/1042633/zutemorenakiduduseg.pdf
- https://site-1042357.mozfiles.com/files/1042357/negujifanifik.pdf
- https://site-1037844.mozfiles.com/files/1037844/jimanuxubuvenafa.pdf
- https://site-1039565.mozfiles.com/files/1039565/17032336125.pdf
- https://site-1040434.mozfiles.com/files/1040434/62357474041.pdf
- https://site-1038510.mozfiles.com/files/1038510/babizerasedabadopufapas.pdf
- https://site-1039449.mozfiles.com/files/1039449/gupobikozigag.pdf
- https://site-1038432.mozfiles.com/files/1038432/19862128049.pdf
- https://fupexorugukemig.weebly.com/uploads/1/3/0/8/130814763/xabowogesemivo_dajexemiwasor_molesaregivako_gewefajabidub.pdf
- https://jivexine.weebly.com/uploads/1/3/1/3/131380908/tinate-koxegoxofadoder-sosakebined.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f86fe843edfa.pdf
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f87212487283.pdf
- https://cdn-cms.f-static.net/uploads/4368746/normal_5f8892dd20141.pdf
- https://cdn-cms.f-static.net/uploads/4368245/normal_5f8821990f3b1.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f87eb74bd98c.pdf
- https://site-1037246.mozfiles.com/files/1037246/64160762747.pdf
- https://site-1043032.mozfiles.com/files/1043032/nefikemokozu.pdf
Embedded domains
- ggtraff.ru
- vuxozajuje.weebly.com
- jakedekokobara.weebly.com
- dutitujazekap.weebly.com
- xonimitofowe.weebly.com
- pepuzategazeg.weebly.com
- site-1036646.mozfiles.com
- site-1043160.mozfiles.com
- site-1042633.mozfiles.com
- site-1042357.mozfiles.com
- site-1037844.mozfiles.com
- site-1039565.mozfiles.com
- site-1040434.mozfiles.com
- site-1038510.mozfiles.com
- site-1039449.mozfiles.com
- site-1038432.mozfiles.com
- fupexorugukemig.weebly.com
- jivexine.weebly.com
- cdn-cms.f-static.net
- site-1037246.mozfiles.com
- site-1043032.mozfiles.com
- site-1041694.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report