SUSPICIOUS — normal_5f87fb3302bc9.pdf
SUSPICIOUS — normal_5f87fb3302bc9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
f55a8e861140d0858c08c552f98198e922ac0ca6073081e9a348e9d4214c96b0 - SHA-1:
7d0c024cb5706cf7674211a78bc1cdba0c408ecb - MD5:
07e3b271c876a9d5933d7b27a7b9f438 - ssdeep:
768:pgGzpDxpTRs7UJF1SGn+AkR9AnhTTmJYwBFVfuUeoONr:KGFFpTG7Ud+AkInVqJYwB/7eoONr - TLSH:
T17F328DF31497DD8CBE879B536CB62596518A8388B1379790498C772DC8ACABC7E00870 - Submitted as: normal_5f87fb3302bc9.pdf
- File type: pdf · Size: 46588 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=epsxe+emulator+apk+revdl, https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/demajawugijudo_narasobabuson.pdf, https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/xenemavurinap_jokepirewiteda_fijalezej_gemewije.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=epsxe+emulator+apk+revdl
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/demajawugijudo_narasobabuson.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/xenemavurinap_jokepirewiteda_fijalezej_gemewije.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/2543267.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/297c0.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/ff06dfdf.pdf
- https://bibeliki.weebly.com/uploads/1/3/0/7/130738572/6202291.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/8108700.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/4328668.pdf
- https://uploads.strikinglycdn.com/files/e7bac124-b207-4757-8311-3ea124155fa7/2789145454.pdf
- https://uploads.strikinglycdn.com/files/7dd7d9bb-403a-4b57-a5a5-68f5105d636d/dukamemijujilop.pdf
- https://uploads.strikinglycdn.com/files/1867c95a-2e29-4bd7-a4ac-b121d27cea9a/68219246393.pdf
- https://rutaluxunenore.weebly.com/uploads/1/3/0/7/130740368/ruxixakukutego.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/kezedivalo-bolumukejufufik.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/zanazanekoxel.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/9707984.pdf
- https://uploads.strikinglycdn.com/files/190a6a33-18cc-4ce2-b744-17e1628a9357/modituzodebuzi.pdf
- https://uploads.strikinglycdn.com/files/25c3d817-0d4e-44da-8cb9-b70ccf556b53/pabevoduduzexe.pdf
- https://uploads.strikinglycdn.com/files/ddef6453-970f-43f5-84bc-075a0f7548dd/9514637272.pdf
- https://uploads.strikinglycdn.com/files/3e480972-1953-4c09-b637-d11e14d97734/97718873085.pdf
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f8782a095575.pdf
- https://cdn-cms.f-static.net/uploads/4367912/normal_5f87ef4df2723.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f86fea170fd7.pdf
- https://cdn-cms.f-static.net/uploads/4367959/normal_5f875fdbd1e44.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- lagukekejase.weebly.com
- vuxozajuje.weebly.com
- jaserasozupog.weebly.com
- guwomenod.weebly.com
- genigudepa.weebly.com
- bibeliki.weebly.com
- vuzevarezevarot.weebly.com
- nanorobudilason.weebly.com
- uploads.strikinglycdn.com
- rutaluxunenore.weebly.com
- dimaxafazeza.weebly.com
- bedizegoresupa.weebly.com
- jukafubu.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report