SUSPICIOUS — normal_5f89c6e3c6821.pdf
SUSPICIOUS — normal_5f89c6e3c6821.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0ed34764dc5ffdb71f3bcbe3a40ce894334b5875a6bd8c1261e0ed960f6314ee - SHA-1:
7ee3e2fcf353596a35e2fda626361598a06911bd - MD5:
bc4362e91c2a295730d615e8dc7ba055 - ssdeep:
768:rgGzpDvpPkm6X9oGiz+lSYplsKqJKM/SLDiYl9WKvTGFr000o3XfOOQpN:UGFjp9KcKHLDiW9WmTUr00LO3pN - TLSH:
T1CF308EF351A7DE8C7A86AF03ADB611A96089DA8D7037DB9044CC762CC47C6FD2E04A51 - Submitted as: normal_5f89c6e3c6821.pdf
- File type: pdf · Size: 38485 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=3d+hologram+wallpaper+mod+apk, https://cdn.shopify.com/s/files/1/0432/2800/4507/files/beauty_and_the_beast_musical_script_act_2.pdf, https://cdn.shopify.com/s/files/1/0496/2484/2391/files/magnavox_flat_screen_tv_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=3d+hologram+wallpaper+mod+apk
- https://cdn.shopify.com/s/files/1/0432/2800/4507/files/beauty_and_the_beast_musical_script_act_2.pdf
- https://cdn.shopify.com/s/files/1/0496/2484/2391/files/magnavox_flat_screen_tv_manual.pdf
- https://cdn.shopify.com/s/files/1/0432/2669/3789/files/zuxojuxu.pdf
- https://cdn.shopify.com/s/files/1/0500/1035/7913/files/luzogerutif.pdf
- https://cdn-cms.f-static.net/uploads/4367648/normal_5f885f8ea010c.pdf
- https://cdn-cms.f-static.net/uploads/4368223/normal_5f88dbe34d156.pdf
- https://cdn-cms.f-static.net/uploads/4372384/normal_5f8972de140ce.pdf
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f87c55a1e0cd.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f87af8b166e9.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f870a6404807.pdf
- https://cdn-cms.f-static.net/uploads/4366405/normal_5f873c8d3d51c.pdf
- https://uploads.strikinglycdn.com/files/9413e818-1bec-4281-bb8e-79fcf9033a60/97934324019.pdf
- https://uploads.strikinglycdn.com/files/9577942e-33ac-4efb-a539-63633eb04689/fimijajejifigefinilejetax.pdf
- https://uploads.strikinglycdn.com/files/5b7e921c-6c9e-4179-aaa9-3ce08f4c1c5e/tasawuselim.pdf
- https://uploads.strikinglycdn.com/files/fa56f367-8aed-47dc-af26-71319629b384/vewejalez.pdf
- https://cdn-cms.f-static.net/uploads/4371524/normal_5f884c5a9bbc6.pdf
- https://cdn-cms.f-static.net/uploads/4369494/normal_5f8954bd65fe7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report