SUSPICIOUS — normal_5f987688885bf.pdf
SUSPICIOUS — normal_5f987688885bf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
32fa851012f0a28fe0233e2ce11fddda779af1a6ee46de6d530c4c6632028f17 - SHA-1:
a5f4d9378fe168ac0d63530830e1cffb4756e14f - MD5:
e85bd34ba2ef932ccd1f2e49adcc11b2 - ssdeep:
768:VgGzpDhpw0h+JuqVz6czRmQgYd/AUPNZ3VcJsV7jApP6ZU/nfaWLvrTg2sTRLPkA:GGFFps/gY//FcJsV6PdnfaWL3lMPz5 - TLSH:
T11D339EF791DBDD8D7A82AB03ADB714652189C78C213797A058887B2CC4BC6BD6E10D70 - Submitted as: normal_5f987688885bf.pdf
- File type: pdf · Size: 51233 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=mens+military+jacket+uk, https://panidulupeju.weebly.com/uploads/1/3/0/9/130969186/luxojafojeminatux.pdf, https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/7294463.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=mens+military+jacket+uk
- https://panidulupeju.weebly.com/uploads/1/3/0/9/130969186/luxojafojeminatux.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/7294463.pdf
- https://kizekusoviwo.weebly.com/uploads/1/3/1/4/131453028/joxufi-nabuba-fumiwi.pdf
- https://dupizonax.weebly.com/uploads/1/3/1/3/131380343/muxupajukagopoje.pdf
- https://uploads.strikinglycdn.com/files/95c17e2b-7b77-4359-b00d-d7734a95e4aa/85091747417.pdf
- https://uploads.strikinglycdn.com/files/6b811f6d-4401-4831-80a1-aa4a14851b07/wonofamive.pdf
- https://uploads.strikinglycdn.com/files/c3194ee5-90e6-4c8d-bcd5-9cad2f1bb5e6/70837429024.pdf
- https://uploads.strikinglycdn.com/files/0a920b91-60e8-4c34-aa3f-12668e9473cf/square_word_calligraphy.pdf
- https://cdn.shopify.com/s/files/1/0436/9635/7530/files/principals_test_reviewer_apk.pdf
- https://cdn.shopify.com/s/files/1/0493/7534/6847/files/zebifitovatevamazag.pdf
- https://uploads.strikinglycdn.com/files/29965e42-18ae-4b95-9763-c0ed6c0d9771/34824945910.pdf
- https://uploads.strikinglycdn.com/files/c767ce66-9e2e-4652-97c9-8599cb62b3f8/boxiluwufojufawoz.pdf
- https://uploads.strikinglycdn.com/files/ec1138e6-ae7f-408c-997b-ecfd523346ac/xajat.pdf
- https://s3.amazonaws.com/jovekus/analysis_of_qualitative_data.pdf
- https://s3.amazonaws.com/vososasoxumete/31810975251.pdf
- https://s3.amazonaws.com/wopari/bass_guitar_exercises_for_dummies_download.pdf
- https://cdn-cms.f-static.net/uploads/4403131/normal_5f95b27de6154.pdf
- https://cdn-cms.f-static.net/uploads/4368751/normal_5f8cefa0e3722.pdf
- https://cdn-cms.f-static.net/uploads/4367646/normal_5f87542a64760.pdf
- https://cdn-cms.f-static.net/uploads/4387571/normal_5f8ebfefef2cb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- panidulupeju.weebly.com
- xebikazogede.weebly.com
- kizekusoviwo.weebly.com
- dupizonax.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report