SUSPICIOUS — normal_5f88a62332305.pdf
SUSPICIOUS — normal_5f88a62332305.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
160f5d918b4500ba4345f0b067e75c19ae9ce2cd6522fe8917589a2700504073 - SHA-1:
1f43cfa307a839a9a1859f948c37889db3b4ab85 - MD5:
97f6f409e2722c7aa1ce13c53e4931a7 - ssdeep:
768:1gGzpDDpSbN3CWZt14KtTMIfG6mMOcM9QDArZ/uXYHkroUbrhypuZ:mGFnpo3CWFvN/DArZ/EYHjUvguZ - TLSH:
T1DD326CF350A7DD8C7A8AAB03AEEF25585049C7486172EBA445CC672DD4BC77E3E00921 - Submitted as: normal_5f88a62332305.pdf
- File type: pdf · Size: 43447 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=hamstring+stretches+nhs+pdf, https://site-1036713.mozfiles.com/files/1036713/kamorinezow.pdf, https://site-1038414.mozfiles.com/files/1038414/48338401162.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=hamstring+stretches+nhs+pdf
- https://site-1036713.mozfiles.com/files/1036713/kamorinezow.pdf
- https://site-1038414.mozfiles.com/files/1038414/48338401162.pdf
- https://site-1038321.mozfiles.com/files/1038321/40852814919.pdf
- https://site-1043842.mozfiles.com/files/1043842/75254252177.pdf
- https://site-1039748.mozfiles.com/files/1039748/pabibagosafatizuda.pdf
- https://site-1039316.mozfiles.com/files/1039316/27311564593.pdf
- https://site-1048220.mozfiles.com/files/1048220/como_entra_na_deep_web_pelo_android.pdf
- https://site-1043477.mozfiles.com/files/1043477/google_drive_searchable.pdf
- https://site-1043565.mozfiles.com/files/1043565/20624032899.pdf
- https://site-1037920.mozfiles.com/files/1037920/rafofavesokojagovuso.pdf
- https://uploads.strikinglycdn.com/files/3bceee9d-611f-4759-bef7-eee801997737/38784486821.pdf
- https://uploads.strikinglycdn.com/files/930341c7-3f88-4e5d-ab7a-aa6d1ff7f0b3/64216955052.pdf
- https://uploads.strikinglycdn.com/files/0df69cf8-c48c-4430-bb38-3c3b4ed3aa2d/67905173462.pdf
- https://uploads.strikinglycdn.com/files/95502f2c-29f3-46d5-b7e7-3d2a7679a986/86566096173.pdf
- https://uploads.strikinglycdn.com/files/d0f46241-2aa7-44e0-b9eb-c51f566f2167/xaruw.pdf
- https://site-1048456.mozfiles.com/files/1048456/zamolarovuvaxidaga.pdf
- https://site-1039634.mozfiles.com/files/1039634/dejaliruwum.pdf
- https://cdn.shopify.com/s/files/1/0432/2630/0575/files/vawaxalunawaxebalutufulo.pdf
- https://cdn.shopify.com/s/files/1/0482/9629/6612/files/how_to_encrypt_file_with_password.pdf
- https://cdn.shopify.com/s/files/1/0437/3918/5303/files/raxesudurepunekeluwal.pdf
- https://cdn.shopify.com/s/files/1/0503/6651/3312/files/zanerixezexaxu.pdf
- https://uploads.strikinglycdn.com/files/30ad8642-91cf-4f8b-a771-e2202948cfc5/37771735720.pdf
- https://uploads.strikinglycdn.com/files/7d99887f-35fb-444f-b164-a2881cc146d1/pesitetixisizir.pdf
- https://uploads.strikinglycdn.com/files/b40e365b-db22-449d-9196-55f2f5c925fc/99317687525.pdf
Embedded domains
- cctraff.ru
- site-1036713.mozfiles.com
- site-1038414.mozfiles.com
- site-1038321.mozfiles.com
- site-1043842.mozfiles.com
- site-1039748.mozfiles.com
- site-1039316.mozfiles.com
- site-1048220.mozfiles.com
- site-1043477.mozfiles.com
- site-1043565.mozfiles.com
- site-1037920.mozfiles.com
- uploads.strikinglycdn.com
- site-1048456.mozfiles.com
- site-1039634.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report