SUSPICIOUS — normal_5f885317aa219.pdf
SUSPICIOUS — normal_5f885317aa219.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
02f4dd50a8d06fcf0061189fa209ba0c7cccd848f84846ca15d9e06fea8ed283 - SHA-1:
2537042b2e252e785e0f714990a8ac30026d6753 - MD5:
8ae70ed8bb8051aa63f2b625ababe5f9 - ssdeep:
768:H3gGzpDNpfGpywVwYhZu5tnQCUBFzmrx728zGeRSBLEcJgvTKFOitQh0SglY2wYp:wGF5pu4GewJ0+FOAWCXXFzlZ - TLSH:
T1F0327CF350A3EC4D3AC78F036EAB1559A48DD7885232E76444CC662CD87C7AD6F40A60 - Submitted as: normal_5f885317aa219.pdf
- File type: pdf · Size: 44842 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=free+audio+recording+app+for+android, https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/10610.pdf, https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/bubutowunaj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=free+audio+recording+app+for+android
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/10610.pdf
- https://rakamukomegu.weebly.com/uploads/1/3/2/6/132681656/bubutowunaj.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/45e0bd986f.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/261add00245.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f86f9aa59a80.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f882efbe4169.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f870a52a8d43.pdf
- https://cdn-cms.f-static.net/uploads/4369486/normal_5f87eeac4d3e0.pdf
- https://cdn-cms.f-static.net/uploads/4366978/normal_5f87419a3b18c.pdf
- https://cdn.shopify.com/s/files/1/0493/7177/5142/files/66060616008.pdf
- https://cdn.shopify.com/s/files/1/0431/5791/3749/files/emoticon_defense_hacked.pdf
- https://cdn.shopify.com/s/files/1/0486/5002/7176/files/how_to_drive_manual_car_in_roundabout.pdf
- https://cdn.shopify.com/s/files/1/0497/5217/8849/files/jotikinetojuxube.pdf
- https://cdn.shopify.com/s/files/1/0476/7626/0518/files/old_house_gardens.pdf
- https://uploads.strikinglycdn.com/files/b90f11b7-a8f9-4177-80f9-277f50c6a8d7/gaxupis.pdf
- https://uploads.strikinglycdn.com/files/e6c72166-cb63-40c9-9ea1-365ce547afae/rifupukopo.pdf
- https://uploads.strikinglycdn.com/files/ef8d039c-330e-4437-9cb8-6c6e92e3cdc9/difepasunorelajofajusaj.pdf
- https://uploads.strikinglycdn.com/files/670ce02d-d487-47b4-b0c3-6c5032760da4/49939916533.pdf
- https://cdn-cms.f-static.net/uploads/4368485/normal_5f87fcbf6cd92.pdf
- https://cdn-cms.f-static.net/uploads/4369659/normal_5f87c85fb8f5b.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f873735e0edd.pdf
- https://cdn-cms.f-static.net/uploads/4367304/normal_5f87cb25bc9eb.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f87447a27a49.pdf
- https://cdn-cms.f-static.net/uploads/4368218/normal_5f87a6fe68d46.pdf
Embedded domains
- cctraff.ru
- jakedekokobara.weebly.com
- rakamukomegu.weebly.com
- xebikazogede.weebly.com
- tavumake.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report