SUSPICIOUS — normal_5f8fe5bf85fcf.pdf
SUSPICIOUS — normal_5f8fe5bf85fcf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
322cdb05be4e4d0c864d0f15bac4aa6e32f8cf0785d83bcbeea84809cd26bfc4 - SHA-1:
a20d1994d9ffb1667ddc60ee45815e0541f09f58 - MD5:
6bf0dcd9aa790e354b3d5819e7593cbe - ssdeep:
768:XgGzpDieoVjng+Dq4/r+lbYF4N3whUedVhzvjfn0wfYc481YO7qTKROp1dz2:wGFOeYg+DqZl0F4NgaedVtvjv0upkf2 - TLSH:
T130348DF310E7ED8C6AC7DB0769AA206E504ADB4D2232E7A44488772CC4BC37D7E55A50 - Submitted as: normal_5f8fe5bf85fcf.pdf
- File type: pdf · Size: 53010 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=google+local+guide+level+perks, https://cdn.shopify.com/s/files/1/0432/6385/2708/files/ff14_crafter_leveling_guide.pdf, https://cdn.shopify.com/s/files/1/0483/9702/5440/files/kizexosexamati.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=google+local+guide+level+perks
- https://cdn.shopify.com/s/files/1/0432/6385/2708/files/ff14_crafter_leveling_guide.pdf
- https://cdn.shopify.com/s/files/1/0483/9702/5440/files/kizexosexamati.pdf
- https://cdn.shopify.com/s/files/1/0486/3374/1480/files/concrete_septic_tank_installation_guide.pdf
- https://s3.amazonaws.com/zetare/91742692134.pdf
- https://s3.amazonaws.com/wonoti/88914231408.pdf
- https://s3.amazonaws.com/jamokaroxoj/tapemesogubewekolukiwak.pdf
- https://s3.amazonaws.com/henghuili-files/rufasazi.pdf
- https://s3.amazonaws.com/xanebavifamopez/amigdalas_cerebrales.pdf
- https://s3.amazonaws.com/gupuso/aristolochia_bracteolata_medicinal_uses.pdf
- https://s3.amazonaws.com/fasanag/18909045803.pdf
- https://uploads.strikinglycdn.com/files/5fdaa8ee-33d2-4490-8050-3f10042a6c99/tukilomazugogepenupogilaw.pdf
- https://uploads.strikinglycdn.com/files/a703f492-7fff-46a4-a8e8-8dfedb32c847/roxivavozopuxix.pdf
- https://uploads.strikinglycdn.com/files/a8ab1280-ea7c-4f38-a85c-83fecc6478f2/9386570510.pdf
- https://wesoxiworikezux.weebly.com/uploads/1/3/1/3/131380467/vemedi.pdf
- https://liwevapazu.weebly.com/uploads/1/3/1/0/131071299/ee1b44a.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/2122744.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/2509795.pdf
- https://wojedebaroz.weebly.com/uploads/1/3/1/6/131637691/bipilule.pdf
- https://uploads.strikinglycdn.com/files/4fde409c-c8ab-4e46-8e60-5ede9fe0d4b4/19038100591.pdf
- https://uploads.strikinglycdn.com/files/6695ab1f-99b9-4b2b-8917-53bbb0a0c07a/71782902645.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- wesoxiworikezux.weebly.com
- liwevapazu.weebly.com
- xojerajap.weebly.com
- fuparududewon.weebly.com
- wojedebaroz.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report