SUSPICIOUS — normal_5f870f845929c.pdf
SUSPICIOUS — normal_5f870f845929c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
15ebc4cd95fcd465ee05d9fd3e5e77c400c6f723cf57d0cfd0ad3094776d1494 - SHA-1:
94bee7758b06e1214dc1ef26ec6fa595c763afe7 - MD5:
d0bbac358f64c470ecd31bca526a90bc - ssdeep:
768:/AgGzpDfp4I3T/48qc+AzcDojhwMPWWMhOAt1PPgHwrP8ohcxcHCqaTaKIDPJX53:lGFDpPqc+aMojeyIOY1PP2aKqPJ557F7 - TLSH:
T12532AEF364D7EE5C7A879B036DAA1569644DCB4C6233EBA0048D672CC4BC1BC6F10A60 - Submitted as: normal_5f870f845929c.pdf
- File type: pdf · Size: 46797 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=download+viber+for+android+uptodown, https://cdn-cms.f-static.net/uploads/4366014/normal_5f8702fcc7324.pdf, https://cdn-cms.f-static.net/uploads/4365607/normal_5f86fe7625878.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=download+viber+for+android+uptodown
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f8702fcc7324.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f86fe7625878.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f8703eedb62c.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/tunitulo.pdf
- https://cdn-cms.f-static.net/uploads/4365545/normal_5f870f5d30d1a.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f86f82adebc0.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f86ff9d65dac.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f870b2d5a57d.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f870a1e96733.pdf
- https://cdn.shopify.com/s/files/1/0483/0461/9684/files/rizubipobobawamuminipej.pdf
- https://cdn.shopify.com/s/files/1/0439/4650/8456/files/xipozutobogusoka.pdf
- https://cdn.shopify.com/s/files/1/0465/2040/2078/files/55225991238.pdf
- https://cdn.shopify.com/s/files/1/0478/9698/5766/files/vutasarumuka.pdf
- https://cdn.shopify.com/s/files/1/0437/5176/8225/files/delixijowofej.pdf
- https://uploads.strikinglycdn.com/files/2a4c8ff2-6f02-4252-bef6-e842ec76f9a2/xozezilesawuler.pdf
- https://uploads.strikinglycdn.com/files/8dc069f6-aeb8-417b-ad2e-cb7b2668a515/34790237621.pdf
- https://uploads.strikinglycdn.com/files/283db7a9-0b0d-4b4f-80be-0d72fc5984e3/41648035837.pdf
- https://uploads.strikinglycdn.com/files/fe236c62-d0b6-4db7-99be-0d83ce75fe4c/56108237499.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f86f7776f3cb.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87085499587.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- dutitujazekap.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report