SUSPICIOUS — normal_5f96cc9d5120c.pdf
SUSPICIOUS — normal_5f96cc9d5120c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f2981fc85540a8ddba163d35a630fd125ab8babaddf78bfede3e7eda87a84c31 - SHA-1:
053b4c1c625ec8af7b5cf07ad1efce6e246b63cf - MD5:
32cf953e70e58aa97470db011b6ee5c4 - ssdeep:
1536:nGFqpa2uebnIERMUDcPZn6a4R0PKa3dvfKCTnu:GFqpd3yUAoa4qrdvSCq - TLSH:
T18534BFF35187EC0C3AC697039DB725AA5108DA49E233A66008DC372DD5BC6BC7E11975 - Submitted as: normal_5f96cc9d5120c.pdf
- File type: pdf · Size: 54313 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/123?keyword=lego+harry+potter+years+1-4+apk+android, https://relugudikovok.weebly.com/uploads/1/3/4/2/134265752/viladekodawitaziz.pdf, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nonasizedugiture.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=lego+harry+potter+years+1-4+apk+android
- https://relugudikovok.weebly.com/uploads/1/3/4/2/134265752/viladekodawitaziz.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nonasizedugiture.pdf
- https://bakuwosir.weebly.com/uploads/1/3/0/8/130874569/3161725.pdf
- https://vaxeratomox.weebly.com/uploads/1/3/4/3/134397216/jifajozopora-gefoxagawurek.pdf
- https://vixeroniwemeful.weebly.com/uploads/1/3/0/7/130740086/fetijitefakuw-sijefedi-sowat.pdf
- https://cdn-cms.f-static.net/uploads/4402261/normal_5f94dc42eca12.pdf
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f93ef101d570.pdf
- https://cdn-cms.f-static.net/uploads/4416660/normal_5f95e0ca5329f.pdf
- https://cdn-cms.f-static.net/uploads/4388272/normal_5f8d3e2a76c0a.pdf
- https://cdn.shopify.com/s/files/1/0433/6146/8571/files/daniwopologu.pdf
- https://cdn.shopify.com/s/files/1/0506/6712/6958/files/auto_follow_instagram_free_apk.pdf
- https://cdn.shopify.com/s/files/1/0436/1791/0947/files/87485923871.pdf
- https://cdn.shopify.com/s/files/1/0500/7107/7027/files/9303195157.pdf
- https://pudegubazamase.weebly.com/uploads/1/3/1/1/131163945/ca311b.pdf
- https://ximazula.weebly.com/uploads/1/3/0/7/130738777/womulesiligawiva.pdf
- https://rojigoziziza.weebly.com/uploads/1/3/4/4/134434225/cc587b372b730f.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/movew.pdf
- https://uploads.strikinglycdn.com/files/2e877d21-adec-4b62-b5c2-fac11f297362/ff9_walkthrough_download.pdf
- https://uploads.strikinglycdn.com/files/8f687615-9961-4ba8-9174-86678f8fbaec/sogize.pdf
- https://uploads.strikinglycdn.com/files/48fc4e85-916f-41f1-ab36-6aec4e1abda2/56097249685.pdf
- https://uploads.strikinglycdn.com/files/c53b627f-17c0-4cd9-b19e-c1c05c8ba9a3/81093552250.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- relugudikovok.weebly.com
- jakedekokobara.weebly.com
- bakuwosir.weebly.com
- vaxeratomox.weebly.com
- vixeroniwemeful.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- pudegubazamase.weebly.com
- ximazula.weebly.com
- rojigoziziza.weebly.com
- jatorogerujew.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report