SUSPICIOUS — normal_5f87b8905237f.pdf
SUSPICIOUS — normal_5f87b8905237f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
5724cdcf4f4a605b7d5c42420f1cee6b1c52689bfebb9643a3676fbcbd97b695 - SHA-1:
708b08c1966e3fb9c5e4b0c9fe4f959c60de43f8 - MD5:
dfd98af172f8616def3848920e4574fc - ssdeep:
768:X5gGzpDUpWjeuo5+8gQ2aYF320KniLArsS5Bl8abcp/IuD+I2X9qn72O1Ek4YToN:qGFYpWjAiLq7Blvbcp/5D+PX9qnytYTa - TLSH:
T1E0329DF31063DD8C3987DB436EE6249DA25AD7C95023A7A454D8762CC47C3BD6F209A0 - Submitted as: normal_5f87b8905237f.pdf
- File type: pdf · Size: 45982 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=pipa+combate+game+android+download, https://cdn-cms.f-static.net/uploads/4365539/normal_5f871c64444f5.pdf, https://cdn-cms.f-static.net/uploads/4366036/normal_5f86fb570c1cd.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=pipa+combate+game+android+download
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f871c64444f5.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f86fb570c1cd.pdf
- https://cdn-cms.f-static.net/uploads/4367905/normal_5f8764a4f3eaf.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f877ac86c87e.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/bdfa22f.pdf
- https://rimesozarabef.weebly.com/uploads/1/3/1/6/131607712/noterufuwuxavo.pdf
- https://cdn.shopify.com/s/files/1/0432/8266/1532/files/8339912573.pdf
- https://cdn.shopify.com/s/files/1/0484/0639/7086/files/maths_for_7_year_olds_worksheets.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/0e0cd.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/87a3a3e4.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/tusog.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f876c1a2bb1e.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f87453ff1179.pdf
- https://cdn.shopify.com/s/files/1/0436/9996/2024/files/is_it_worth_it_let_me_work_it_old_lady.pdf
- https://cdn.shopify.com/s/files/1/0438/5911/6182/files/jbl_endurance_jump_review.pdf
- https://cdn.shopify.com/s/files/1/0434/2746/3324/files/the_interpersonal_communication_book_14th_edition_free.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- jaserasozupog.weebly.com
- rimesozarabef.weebly.com
- cdn.shopify.com
- vuzevarezevarot.weebly.com
- jawowigo.weebly.com
- juragubiv.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report