SUSPICIOUS — normal_5f94f5ed61c7a.pdf
SUSPICIOUS — normal_5f94f5ed61c7a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
3a3d15d82fd7d4e0414696da487dde553459d08080e58bc805eb7e55deb31aa8 - SHA-1:
071be169d47982eb5c6d2e2f15fd9d4435437c19 - MD5:
c7fd400f444b089fd0e0501d9fc64cce - ssdeep:
768:iwgGzpDb5aGFPV2NxZhB99evvQexLxFhNN8athmcZpda:yGFxNINxzhedNNLtMcZpda - TLSH:
T13832AEF3449BDD8C79C75713ADB61129558AC788A0268BA409CCB63CC4BCAFE6F11D50 - Submitted as: normal_5f94f5ed61c7a.pdf
- File type: pdf · Size: 44359 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=android+google+account+manager+download, https://uploads.strikinglycdn.com/files/6fc5035c-fd1c-41ad-afa2-af32b3688b03/kojig.pdf, https://uploads.strikinglycdn.com/files/0756e5cc-b23b-4a6a-a451-524a8c8fc58e/43754847841.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=android+google+account+manager+download
- https://uploads.strikinglycdn.com/files/6fc5035c-fd1c-41ad-afa2-af32b3688b03/kojig.pdf
- https://uploads.strikinglycdn.com/files/0756e5cc-b23b-4a6a-a451-524a8c8fc58e/43754847841.pdf
- https://uploads.strikinglycdn.com/files/dc8c077b-3e28-4bb7-93b5-801ee204fb89/android_oyun_club_subway_surf_hile_indir.pdf
- https://uploads.strikinglycdn.com/files/b6e86559-db75-4cf6-8aef-b7a6c60d2718/58296951053.pdf
- https://cdn.shopify.com/s/files/1/0495/0435/4463/files/ninukerowonaj.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/nexuwa_jopiteralaxo.pdf
- https://kiseridebajesa.weebly.com/uploads/1/3/1/4/131408791/1813485.pdf
- https://xibogunef.weebly.com/uploads/1/3/1/3/131398295/6301211.pdf
- https://tabuxeniki.weebly.com/uploads/1/3/2/6/132682737/loniwof.pdf
- https://sakuvida.weebly.com/uploads/1/3/0/7/130775714/ronefaleb-japometowubig-ravagugulani.pdf
- https://rogidalot.weebly.com/uploads/1/3/1/6/131636841/4287622.pdf
- https://wozofawado.weebly.com/uploads/1/3/0/8/130874325/sikaxusida-fojun-nobuvugoxoguto-jamutugoxenig.pdf
- https://folukufisika.weebly.com/uploads/1/3/1/3/131384255/d41a80ef933e7be.pdf
- https://cdn-cms.f-static.net/uploads/4368748/normal_5f8863361610f.pdf
- https://cdn-cms.f-static.net/uploads/4380545/normal_5f9051f822e83.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f876cb355dd2.pdf
- https://cdn-cms.f-static.net/uploads/4393502/normal_5f94c4371f2c7.pdf
- https://cdn-cms.f-static.net/uploads/4381740/normal_5f8e31c943bb2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- besiwalufeg.weebly.com
- kiseridebajesa.weebly.com
- xibogunef.weebly.com
- tabuxeniki.weebly.com
- sakuvida.weebly.com
- rogidalot.weebly.com
- wozofawado.weebly.com
- folukufisika.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report