SUSPICIOUS — normal_5f88a4c87f9a9.pdf
SUSPICIOUS — normal_5f88a4c87f9a9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
08408a1e59c136b39e47d163b845c18e4e57180287c1688694831612fe474854 - SHA-1:
f51f5603d4bde0c81da73e9f3607b3ec870c8ea8 - MD5:
35d6db87ab7a8f375edf1f26726e514f - ssdeep:
1536:UGFsp5/vK3vWmkmlxghjzOQ1Ag7tvaOZdT64:hFsp59mkmHgpzByg5yOjTN - TLSH:
T17634AFF31097DE4C3A87CB87A9EE349D9046C6886033AB605588772DC8BCBBC6F50551 - Submitted as: normal_5f88a4c87f9a9.pdf
- File type: pdf · Size: 54087 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=baladas+do+amor+ao+vento+pdf, https://site-1043850.mozfiles.com/files/1043850/guvererobiludanujeviv.pdf, https://site-1038864.mozfiles.com/files/1038864/fekiduduxomimawuxidiza.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=baladas+do+amor+ao+vento+pdf
- https://site-1043850.mozfiles.com/files/1043850/guvererobiludanujeviv.pdf
- https://site-1038864.mozfiles.com/files/1038864/fekiduduxomimawuxidiza.pdf
- https://site-1038774.mozfiles.com/files/1038774/53635936486.pdf
- https://cdn.shopify.com/s/files/1/0496/6006/7991/files/jurassic_park_fat_guy_death.pdf
- https://cdn.shopify.com/s/files/1/0500/5144/9000/files/millikan_atomic_theory_experiment.pdf
- https://cdn.shopify.com/s/files/1/0432/2764/4072/files/87325363915.pdf
- https://cdn.shopify.com/s/files/1/0479/1979/2294/files/11846132033.pdf
- https://cdn.shopify.com/s/files/1/0499/5068/7387/files/64599882698.pdf
- https://site-1042286.mozfiles.com/files/1042286/ribevu.pdf
- https://site-1038650.mozfiles.com/files/1038650/zajinavivapanuritovizake.pdf
- https://uploads.strikinglycdn.com/files/85f72356-8b5e-417d-9456-0815fb00b96d/8394213410.pdf
- https://uploads.strikinglycdn.com/files/2c2a1bbc-b408-4787-8989-40e2641b6102/7039424651.pdf
- https://uploads.strikinglycdn.com/files/1ab77c0e-e1f8-4a33-ad7b-ff9c447c9ec4/70058964121.pdf
- https://uploads.strikinglycdn.com/files/ac148a8a-8f61-42f3-b102-da15bb1ea4bb/wagurev.pdf
- https://uploads.strikinglycdn.com/files/9a2388e4-9463-4db9-a41f-cb8e276747d6/kisigujo.pdf
- https://cdn-cms.f-static.net/uploads/4366325/normal_5f876051b3c6d.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f8810e1a44aa.pdf
- https://cdn.shopify.com/s/files/1/0430/8389/0850/files/indirect_function_excel_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0434/9712/8088/files/bunn_my_cafe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- site-1043850.mozfiles.com
- site-1038864.mozfiles.com
- site-1038774.mozfiles.com
- cdn.shopify.com
- site-1042286.mozfiles.com
- site-1038650.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report