SUSPICIOUS — normal_5f8a0531c6951.pdf
SUSPICIOUS — normal_5f8a0531c6951.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0cdc05989c975ea15d265c11e0bd7a5224e35924a777d28b7aace3350f535de6 - SHA-1:
e71d1f04eb930a572b1ac4c910d182049fed6d9e - MD5:
a2396c18a544af52f494d6b748abd803 - ssdeep:
768:dgGzpD0pVbG2ZBy2fx5gn1MR//U/gw5VKR3WM1u1VnnmnV7:eGFApJEMBXwz5VmnV7 - TLSH:
T17A32BEF310D7DC8C3A8BAB439CB72446548AC78C6237A761449C7B2CA4BC57D7E10965 - Submitted as: normal_5f8a0531c6951.pdf
- File type: pdf · Size: 43815 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=approaches+to+psychology+worksheet, https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/wirefokopewa_logud.pdf, https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/ad9d4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=approaches+to+psychology+worksheet
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/wirefokopewa_logud.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/ad9d4.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/9031774.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/51e0550d119f.pdf
- https://godadonalizubo.weebly.com/uploads/1/3/1/4/131437317/9e77629c551b87a.pdf
- https://dokodajibebabek.weebly.com/uploads/1/3/2/3/132302773/nesibuganut.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/8997904d1d1210.pdf
- https://uploads.strikinglycdn.com/files/73cbbcc4-cb45-4ad6-a31c-3b61ece77731/l_assassin_habite__ct.pdf
- https://uploads.strikinglycdn.com/files/bbde3f3c-1556-4920-8ba3-e8fad8e5464e/74218768568.pdf
- https://uploads.strikinglycdn.com/files/e583a594-1472-4cc6-969a-eb07e0540199/26672093631.pdf
- https://cdn.shopify.com/s/files/1/0432/2036/9576/files/rational_functions_and_their_graphs_quiz_part_2.pdf
- https://cdn.shopify.com/s/files/1/0434/0105/2321/files/wotinagibosetetunefuma.pdf
- https://cdn.shopify.com/s/files/1/0432/1030/9787/files/11678749705.pdf
- https://uploads.strikinglycdn.com/files/995e91b8-90ce-4945-a7ee-69bdf87b77ef/95339376612.pdf
- https://uploads.strikinglycdn.com/files/ac76752c-6de1-4a1e-a2a2-71cb4ca5dca7/sokavawinidegilod.pdf
- https://uploads.strikinglycdn.com/files/23ef5260-dd4c-468d-9990-6c1fc1ffc6d7/liwezove.pdf
- https://uploads.strikinglycdn.com/files/8a56fc57-dc2c-4388-bc07-b3f1774bc0ca/7850975371.pdf
- https://cdn-cms.f-static.net/uploads/4366660/normal_5f87a5eeafde9.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f87363576d64.pdf
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f8786330f993.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- dutitujazekap.weebly.com
- pumowurunumig.weebly.com
- vuxozajuje.weebly.com
- wepugimi.weebly.com
- godadonalizubo.weebly.com
- dokodajibebabek.weebly.com
- jamuseramomuf.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report