SUSPICIOUS — normal_5f8cc1e8d25c7.pdf
SUSPICIOUS — normal_5f8cc1e8d25c7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4f59a127514c977969ae023a2d01eb3a04fdc18cb2e7cc712634a6dee5247c4e - SHA-1:
748090532e83c851f23bf7e039de87024205334f - MD5:
51fc436c5195d5a2ae9d6717e7dd2077 - ssdeep:
1536:CGFpeHqIySFnfgBwqlcg911zcceZWrXtEt:7FpeHPZFlqlVecesrM - TLSH:
T108338EF310A7DD8C7687AB53ADB70498614AC7896236C76044D8B63CC9BC6ADBF10950 - Submitted as: normal_5f8cc1e8d25c7.pdf
- File type: pdf · Size: 51637 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=fontes+de+energia+el%25C3%25A9trica+pdf, https://uploads.strikinglycdn.com/files/07506d5b-50cb-4753-a735-415e56397483/carrie_cabri_witt.pdf, https://uploads.strikinglycdn.com/files/107cc7ea-9b31-4899-8c3a-df3ef71412a3/xaful.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.ru/123?keyword=fontes+de+energia+el%25C3%25A9trica+pdf
- https://uploads.strikinglycdn.com/files/07506d5b-50cb-4753-a735-415e56397483/carrie_cabri_witt.pdf
- https://uploads.strikinglycdn.com/files/107cc7ea-9b31-4899-8c3a-df3ef71412a3/xaful.pdf
- https://uploads.strikinglycdn.com/files/cca37b0f-7b3e-473b-b927-66510777be15/pizojo.pdf
- https://uploads.strikinglycdn.com/files/5b002a3d-9d1f-4cdc-aebc-b74f820e1bf2/22029744790.pdf
- https://uploads.strikinglycdn.com/files/1aebfb88-2022-4257-9995-fd193d262862/80162327200.pdf
- https://uploads.strikinglycdn.com/files/3c06ee58-101f-4ec0-a213-cc10d4c1c5db/80583859579.pdf
- https://uploads.strikinglycdn.com/files/c95cb682-3924-4a39-9933-cff9147e79cd/67316525132.pdf
- https://cdn.shopify.com/s/files/1/0492/9431/1580/files/vujepedavegi.pdf
- https://cdn.shopify.com/s/files/1/0432/3439/4276/files/vapopekovakakapi.pdf
- https://cdn.shopify.com/s/files/1/0431/5699/6245/files/dog_whining_at_night_suddenly.pdf
- https://cdn.shopify.com/s/files/1/0481/3225/9991/files/46889369649.pdf
- https://cdn.shopify.com/s/files/1/0497/6050/1921/files/slow_shopping_thrapie.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/lukuxaluk.pdf
- https://bebamewikirebu.weebly.com/uploads/1/3/0/8/130874540/losig_mezifiji_wosuxexa.pdf
- https://uploads.strikinglycdn.com/files/47c4b3d3-8ac1-4976-b047-e21787aeba9e/caracteristicas_organolepticas_del_pescado.pdf
- https://uploads.strikinglycdn.com/files/d1033a78-28db-4b66-aedf-49f2b9909d9e/vadimikixenegasiv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- bedizegoresupa.weebly.com
- bebamewikirebu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report