SUSPICIOUS — normal_5f87804812d0c.pdf
SUSPICIOUS — normal_5f87804812d0c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1a7c37db15267914850250015dbacca748acd019d1169b27f00ddc9983cfbe7a - SHA-1:
fc9d41cca6c67c6274f854a7c00ab7b438b7eeea - MD5:
bdb0a4be49d026ccf9e8bee12b865e10 - ssdeep:
768:LgGzpD4ppwqWMiQMZWFwIWaQpIgmlQS0I1JWdqITbYeSxHFy41J6UVz:0GFspy0wkQxTbYeSxAkJdVz - TLSH:
T1D2338DF314D7EC8CB9CA9B076DAB2959108D8389B276E35044DC662DC5BCABD7E00C61 - Submitted as: normal_5f87804812d0c.pdf
- File type: pdf · Size: 50678 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=folklore+stories+from+around+the+world+pdf, https://gidixelasulam.weebly.com/uploads/1/3/0/7/130739099/8690333.pdf, https://kidunaxu.weebly.com/uploads/1/3/1/4/131437100/7707936.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=folklore+stories+from+around+the+world+pdf
- https://gidixelasulam.weebly.com/uploads/1/3/0/7/130739099/8690333.pdf
- https://kidunaxu.weebly.com/uploads/1/3/1/4/131437100/7707936.pdf
- https://kidunaxu.weebly.com/uploads/1/3/1/4/131437100/zifanijuloxorog.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/mosajesu_wegeger_wizifelem.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/xusavu_zerezujikewe_vikepegujojaluw_duvorafof.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/kasawo-rakereroboxit-wuzunirib-midagawatebogef.pdf
- https://pobezewimo.weebly.com/uploads/1/3/2/6/132681951/87841b.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/c25f730.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f875c0ccbeb8.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f876d2ba6321.pdf
- https://cdn-cms.f-static.net/uploads/4367279/normal_5f876ef252b84.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f870f879ae1c.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f87557e137dc.pdf
- https://uploads.strikinglycdn.com/files/be06b38c-7ddd-47b1-a32d-12ecbf8ae05b/90779955395.pdf
- https://uploads.strikinglycdn.com/files/e8ac5365-b29b-4c72-8897-4378c002cfb4/8722522079.pdf
- https://uploads.strikinglycdn.com/files/20c3be11-e527-4adc-9d7b-33e910f79393/talexezedekenag.pdf
- https://uploads.strikinglycdn.com/files/3ddcf12b-16a8-4b00-b3b2-f02f6fda6656/43802808549.pdf
- https://uploads.strikinglycdn.com/files/1358ef32-0478-4875-b6dc-f254ba05672e/34390531543.pdf
- https://site-1042875.mozfiles.com/files/1042875/xijijosupobaf.pdf
- https://site-1037878.mozfiles.com/files/1037878/10606119901.pdf
- https://site-1038414.mozfiles.com/files/1038414/39141980346.pdf
- https://site-1039528.mozfiles.com/files/1039528/48613666819.pdf
- https://uploads.strikinglycdn.com/files/53a64009-0bfb-4384-930b-725a2390370a/70439835892.pdf
- https://uploads.strikinglycdn.com/files/a95df25d-cd15-409c-909a-90e12ae4a06b/rowuterifotin.pdf
Embedded domains
- cctraff.ru
- gidixelasulam.weebly.com
- kidunaxu.weebly.com
- jaserasozupog.weebly.com
- pigogokeda.weebly.com
- jamuseramomuf.weebly.com
- pobezewimo.weebly.com
- gevafitasib.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1042875.mozfiles.com
- site-1037878.mozfiles.com
- site-1038414.mozfiles.com
- site-1039528.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report