SUSPICIOUS — normal_5f8e3de0308c5.pdf
SUSPICIOUS — normal_5f8e3de0308c5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
0bc7440bc28e265983bca9744ba19992f71539e7f5d71f4badd4846b0a9c769a - SHA-1:
22ff074cfb29c850879fdd7736bf3b6ac41391c6 - MD5:
ab8588f17e0f1bc554b57e5dd5de1f1a - ssdeep:
768:3gGzpDdpYn8ySewKC/jCURMTstRwAP7+/xg1XqWz7P+slw+WeUnP0qNSjmqczjfq:QGFJpYExl33lw+PUnPhNQOzjfsLNSO - TLSH:
T162328DF350D7EC4C7B4F6B436DAB11A92089D289A526DB5049CC762CC47CBBE6F00A51 - Submitted as: normal_5f8e3de0308c5.pdf
- File type: pdf · Size: 45314 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=whirlpool+built-in+oven+instruction+manual, https://cdn.shopify.com/s/files/1/0484/6898/3969/files/manual_seat_ibiza_style_2020.pdf, https://cdn.shopify.com/s/files/1/0486/0752/7077/files/48776855394.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=whirlpool+built-in+oven+instruction+manual
- https://cdn.shopify.com/s/files/1/0484/6898/3969/files/manual_seat_ibiza_style_2020.pdf
- https://cdn.shopify.com/s/files/1/0486/0752/7077/files/48776855394.pdf
- https://cdn.shopify.com/s/files/1/0493/7534/6847/files/multimedia_computing_gerald_friedland.pdf
- https://cdn.shopify.com/s/files/1/0435/5899/4088/files/ledabepoxeg.pdf
- https://cdn.shopify.com/s/files/1/0499/4246/2618/files/polytone_mini_brute_ii_service_manual.pdf
- https://cdn-cms.f-static.net/uploads/4375528/normal_5f8bed115f7b2.pdf
- https://cdn-cms.f-static.net/uploads/4366973/normal_5f872d382722d.pdf
- https://cdn-cms.f-static.net/uploads/4368469/normal_5f87b6531648a.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f8719e8638c8.pdf
- https://cdn-cms.f-static.net/uploads/4378378/normal_5f8b220a004ed.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f870cda3fb82.pdf
- https://cdn-cms.f-static.net/uploads/4369783/normal_5f8ae76917949.pdf
- https://cdn-cms.f-static.net/uploads/4391903/normal_5f8e0cf3a483d.pdf
- https://cdn-cms.f-static.net/uploads/4381730/normal_5f8bf62d8bd18.pdf
- https://uploads.strikinglycdn.com/files/b4380ed3-f3bd-4905-bd88-b2c8b1c12446/rozedo.pdf
- https://uploads.strikinglycdn.com/files/6b11a69f-427e-4ece-88e4-a7121ac0f5d0/tudiribasimotizamir.pdf
- https://uploads.strikinglycdn.com/files/6440f177-17b2-4e69-80ba-2649be25a459/84591767450.pdf
- https://uploads.strikinglycdn.com/files/f98e877c-bf06-44ec-abf5-fd406bb737c0/taxurukewisabosik.pdf
- https://uploads.strikinglycdn.com/files/f64c32e5-1d42-4416-9879-1fac5a907b21/jemuwofexupukux.pdf
- https://cdn.shopify.com/s/files/1/0268/7477/3694/files/vezijezoxafalixovaz.pdf
- https://cdn.shopify.com/s/files/1/0496/6344/3101/files/fatigue_in_pregnancy_icd_10.pdf
- https://cdn.shopify.com/s/files/1/0499/1480/6440/files/fiskars_tree_pruner_rope_change.pdf
- https://cdn.shopify.com/s/files/1/0432/0319/9138/files/naruto_shippuden_filler_arc_guide.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report