SUSPICIOUS — normal_5f872ee2978a6.pdf
SUSPICIOUS — normal_5f872ee2978a6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0c688dc79de288c5ff121db0670ae3905ad5807a732450018a195fa66da9eba9 - SHA-1:
16793adc5a723e66908d3fd1f23aba85270cf251 - MD5:
b20ab3d1b9de676f7170884dd1e02f8d - ssdeep:
768:HgGzpDrpxuWlE2B6h4XUCBJLLPc/5lBh7goVFOtYyy/Buw7bmLLqs:AGFPp0sU5/T7HVFLwLLqs - TLSH:
T16F32AFF750E3EC8CB98B9B835DB724596189D388213397604889B76DC4BCB7DBD14A20 - Submitted as: normal_5f872ee2978a6.pdf
- File type: pdf · Size: 46044 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=oxford+advanced+learner%2527s+dictionary+apkpure, https://site-1041865.mozfiles.com/files/1041865/26039358779.pdf, https://site-1041579.mozfiles.com/files/1041579/jajokobus.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=oxford+advanced+learner%2527s+dictionary+apkpure
- https://site-1041865.mozfiles.com/files/1041865/26039358779.pdf
- https://site-1041579.mozfiles.com/files/1041579/jajokobus.pdf
- https://site-1038739.mozfiles.com/files/1038739/gomonubekimutajate.pdf
- https://site-1043884.mozfiles.com/files/1043884/muzewab.pdf
- https://uploads.strikinglycdn.com/files/4d8815f7-c579-416e-9421-59518b0284d9/22755896089.pdf
- https://uploads.strikinglycdn.com/files/747cb5df-b530-4a7d-a405-287888dbf4e8/lowogebivuzojoji.pdf
- https://uploads.strikinglycdn.com/files/0f897d8b-bcac-49a3-8fbd-66dc1f99baf9/dofoxisiz.pdf
- https://uploads.strikinglycdn.com/files/2ba20a0b-fae8-4c88-8bfa-9037b573aebe/lapomi.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/fakesonadusiza_nenuned.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf
- https://uploads.strikinglycdn.com/files/eb87162b-6747-4ad5-b31b-a1f5280deba3/kolesuwasugasubotenexakis.pdf
- https://uploads.strikinglycdn.com/files/a852b80e-c64f-4d8d-b59a-9944f12e5e66/gubuf.pdf
- https://uploads.strikinglycdn.com/files/8f53110f-9a15-43f9-94f0-ac9212a33743/fagevagixudokij.pdf
- https://uploads.strikinglycdn.com/files/01cb2449-692a-4e81-9b6c-60361ec1825e/viwanevinavaputozerafipox.pdf
- https://uploads.strikinglycdn.com/files/73316f7d-b410-422b-89f9-bde8dfc4dd32/ximejubaramomeluxazujetos.pdf
- https://uploads.strikinglycdn.com/files/0ad5c9e2-7278-4946-8185-e9ebf490cd99/93057963865.pdf
- https://uploads.strikinglycdn.com/files/545160a0-3616-4540-93d0-1f79f53cc86c/34187992962.pdf
- https://uploads.strikinglycdn.com/files/27bffa0c-2ea1-46d9-bce0-07551741336f/sasageliligeg.pdf
- https://site-1042348.mozfiles.com/files/1042348/fegevamijuwotadibavi.pdf
- https://site-1042830.mozfiles.com/files/1042830/93858384973.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- site-1041865.mozfiles.com
- site-1041579.mozfiles.com
- site-1038739.mozfiles.com
- site-1043884.mozfiles.com
- uploads.strikinglycdn.com
- povutepumik.weebly.com
- dutitujazekap.weebly.com
- site-1042348.mozfiles.com
- site-1042830.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report