SUSPICIOUS — normal_5f95385fee96c.pdf
SUSPICIOUS — normal_5f95385fee96c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
33c63cf4bbec248b3ca7f723c0563f73f3cd86e386190fdefab04b835baa7729 - SHA-1:
80676175e228f084a62f20bd898f158d81928749 - MD5:
24fd6f9eeccb0bf4183ffeb6118fe1f2 - ssdeep:
768:zgGzpDQ6zFTi+IeItZDA3K8oYxSthoU6woeTmTEv84qbwwjr89:MGFk6zNhQA3foYEtoeTmwlqbwkr89 - TLSH:
T10233AEF34097ED8C7A8AA743ADFB22616589D7487237DBA0088C762DC47C17DBE10860 - Submitted as: normal_5f95385fee96c.pdf
- File type: pdf · Size: 48322 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=killer+bean+unleashed+all+weapons+unlocked+apk, https://cdn-cms.f-static.net/uploads/4374178/normal_5f915f1c08fdc.pdf, https://cdn-cms.f-static.net/uploads/4383460/normal_5f922c7e64e8d.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=killer+bean+unleashed+all+weapons+unlocked+apk
- https://s3.amazonaws.com/zizene/bsf_full_form_in_english.pdf
- https://s3.amazonaws.com/susopuzupure/basic_knowledge_of_civil_engineering_for_interview.pdf
- https://s3.amazonaws.com/rovuweraja/lemefizufifenina.pdf
- https://s3.amazonaws.com/gupuso/ravafudumusumepi.pdf
- https://s3.amazonaws.com/leguvefu/anthony_bourdain_typhoid_mary.pdf
- https://s3.amazonaws.com/dukajevo/alfa_romeo_giulietta_2015_brochure.pdf
- https://s3.amazonaws.com/memul/camera_lenses_types.pdf
- https://s3.amazonaws.com/gupuso/microbiologia_bacterias_gram_positivas.pdf
- https://cdn-cms.f-static.net/uploads/4374178/normal_5f915f1c08fdc.pdf
- https://cdn-cms.f-static.net/uploads/4383460/normal_5f922c7e64e8d.pdf
- https://cdn-cms.f-static.net/uploads/4377662/normal_5f8f6c54ccde9.pdf
- https://uploads.strikinglycdn.com/files/9144e0be-57d7-4048-b5ca-37554b9d5887/15833354884.pdf
- https://uploads.strikinglycdn.com/files/604c8680-b707-4f9d-83b7-a05ba66363b7/daduvopesiruxomuliribal.pdf
- https://uploads.strikinglycdn.com/files/fb866696-63ef-48d5-828d-a170239dea69/vogij.pdf
- https://uploads.strikinglycdn.com/files/f6b3b845-b2d7-4409-8cf3-f892f3de2f6d/jevetide.pdf
- https://uploads.strikinglycdn.com/files/328f86d5-88d0-49c7-8208-b74da930d899/40578639216.pdf
- https://s3.amazonaws.com/minaxigevani/semezerexunolidelafod.pdf
- https://s3.amazonaws.com/sivanira/dress_pattern_making_books.pdf
- https://s3.amazonaws.com/xakapudakadu/aces_high_guitar_tab.pdf
- https://s3.amazonaws.com/zabevog/joint_probability.pdf
- https://s3.amazonaws.com/wonoti/7581877062.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report