SUSPICIOUS — normal_5f8826ea21f22.pdf
SUSPICIOUS — normal_5f8826ea21f22.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
070d76d93537762cb4a04dc9641e9fc6bb5c6330546bc5350d87773d69164c65 - SHA-1:
579c34b712974a1116d2b01a5e98fbea08e609e5 - MD5:
6520a0aec13c5212c2a5eca81c6ad075 - ssdeep:
1536:tGF+pbyd2LE5Y9cqb/5RW2KrQv2khvFBqEsIIX:wF+pbyhQ5RWQv2khrqEsh - TLSH:
T14334AEF38293ED8C7A4BAB03ADE610696149DB8D2032C6A059DD7B1CD4BC3FD6E41950 - Submitted as: normal_5f8826ea21f22.pdf
- File type: pdf · Size: 55597 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=polycythemia+in+newborn+pdf, https://cdn-cms.f-static.net/uploads/4366947/normal_5f87a0e379a82.pdf, https://cdn-cms.f-static.net/uploads/4366306/normal_5f87c0f2792f0.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=polycythemia+in+newborn+pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f87a0e379a82.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f87c0f2792f0.pdf
- https://cdn-cms.f-static.net/uploads/4366304/normal_5f87ab8ddde8e.pdf
- https://cdn-cms.f-static.net/uploads/4368964/normal_5f878cfc69caa.pdf
- https://uploads.strikinglycdn.com/files/3bde07d5-dcd4-4713-bf72-a8eb362f197a/karipakadesipixajofa.pdf
- https://uploads.strikinglycdn.com/files/2a1dc226-9e26-4436-ad1d-a9e8333307ff/luxigaribuga.pdf
- https://uploads.strikinglycdn.com/files/6aecbcc0-1044-44ae-b9eb-80c14ec492fa/28269338719.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/8767144.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3532345.pdf
- https://uploads.strikinglycdn.com/files/2d88e9f3-9df3-4cd6-b918-cf7b20ca0d6b/wuregirulo.pdf
- https://uploads.strikinglycdn.com/files/837d49d0-d568-4e77-a92d-e39c45e1a4d2/luxarila.pdf
- https://site-1039954.mozfiles.com/files/1039954/2633773937.pdf
- https://site-1042785.mozfiles.com/files/1042785/dutekixajipun.pdf
- https://site-1041181.mozfiles.com/files/1041181/vamiwapurabomoputifu.pdf
- https://site-1039846.mozfiles.com/files/1039846/16639714674.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- dimaxafazeza.weebly.com
- zoxuzuxebexot.weebly.com
- site-1039954.mozfiles.com
- site-1042785.mozfiles.com
- site-1041181.mozfiles.com
- site-1039846.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report