SUSPICIOUS — normal_5f8e9ca8bddda.pdf
SUSPICIOUS — normal_5f8e9ca8bddda.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
365daf13929521dbe1f35ddd212a6d4a30f02eb4abe893bebce0f3ae9f16aba2 - SHA-1:
1d75f510c9545f2422f5ccd76befb3e13e9baa2f - MD5:
92763d56575d08dce3779a0c71f348aa - ssdeep:
1536:oGFqp1X6iXXbF3/z2iTgZtoShxv597Dpw:FFqp1X6GLF3/zEtoAxv597S - TLSH:
T1B933AEF350A7EC8C7A8B57036EB71559618AC389A136E75014C87B3CD4BC6AD7F20861 - Submitted as: normal_5f8e9ca8bddda.pdf
- File type: pdf · Size: 50407 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=gimp+for+android+phone, https://cdn.shopify.com/s/files/1/0484/0256/3232/files/fubulivov.pdf, https://cdn.shopify.com/s/files/1/0434/4548/5725/files/zipper_pouch_sewing_instructions.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=gimp+for+android+phone
- https://cdn.shopify.com/s/files/1/0484/0256/3232/files/fubulivov.pdf
- https://cdn.shopify.com/s/files/1/0434/4548/5725/files/zipper_pouch_sewing_instructions.pdf
- https://cdn.shopify.com/s/files/1/0493/5371/9964/files/ps2_emulator_for_android_apk_with_bios.pdf
- https://cdn.shopify.com/s/files/1/0497/9671/0561/files/xasuridusetemegodi.pdf
- https://uploads.strikinglycdn.com/files/88376275-ffa6-4986-b93a-445badb6058f/punosur.pdf
- https://uploads.strikinglycdn.com/files/d2563e83-f61c-4786-bf97-0ed36a44eafc/69464942858.pdf
- https://uploads.strikinglycdn.com/files/fedf01a2-b629-462d-be0f-ee51a5ca8f5c/28565915809.pdf
- https://uploads.strikinglycdn.com/files/c5edb57d-3903-45f0-a633-56967b250e6d/71541246064.pdf
- https://wipomozexabezi.weebly.com/uploads/1/3/0/7/130776841/3822180.pdf
- https://wozuwonasanava.weebly.com/uploads/1/3/1/4/131483955/dbab0b62cef.pdf
- https://dubuzosokiboxof.weebly.com/uploads/1/3/1/1/131163723/8503670.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/lebetise-letefivex-jamolojosataxuz.pdf
- https://virataxutepubom.weebly.com/uploads/1/3/0/8/130874282/vesoruzabidoxe_gotos_xaduradizozasoj.pdf
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/cfb93.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/6431815.pdf
- https://cdn-cms.f-static.net/uploads/4367940/normal_5f8b6c7c9f251.pdf
- https://cdn-cms.f-static.net/uploads/4374703/normal_5f8d44c33c289.pdf
- https://cdn-cms.f-static.net/uploads/4368235/normal_5f8785c328d28.pdf
- https://cdn-cms.f-static.net/uploads/4375887/normal_5f8a4093800f7.pdf
- https://cdn-cms.f-static.net/uploads/4369174/normal_5f8a6fb903ae5.pdf
- https://korebamo.weebly.com/uploads/1/3/0/7/130739662/d69b6c.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/vovalukafiluzasafudu.pdf
- https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/fipet_dekomejuw_vijurom_zoxojulevesi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- wipomozexabezi.weebly.com
- wozuwonasanava.weebly.com
- dubuzosokiboxof.weebly.com
- jawowigo.weebly.com
- virataxutepubom.weebly.com
- bizumoku.weebly.com
- jakedekokobara.weebly.com
- cdn-cms.f-static.net
- korebamo.weebly.com
- netaluzubik.weebly.com
- mefemanodi.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report