SUSPICIOUS — normal_5f88151e38ce4.pdf
SUSPICIOUS — normal_5f88151e38ce4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
605d829d828c8afab52848fafd646d793f40989948ee758327ff9db663a46070 - SHA-1:
35fc02e09a1bc41a2e7b4997221e98144c37d039 - MD5:
1b868b95c62ec518ddf0b54875dc315b - ssdeep:
1536:6GFWpKhYI1f0YDafOkYhttjWAuqWD3R7QP:jFWp41f0rfOkYhbaAAD3Rc - TLSH:
T1D5338DF7009BDD8D7E8B9B03ADAB25296089C78D6123CB904988376DD47C67D7E20C61 - Submitted as: normal_5f88151e38ce4.pdf
- File type: pdf · Size: 52326 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=hakeem+luqman+ke+nuskhe+urdu+pdf, https://site-1037215.mozfiles.com/files/1037215/pufitani.pdf, https://site-1039838.mozfiles.com/files/1039838/42708131131.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=hakeem+luqman+ke+nuskhe+urdu+pdf
- https://site-1037215.mozfiles.com/files/1037215/pufitani.pdf
- https://site-1039838.mozfiles.com/files/1039838/42708131131.pdf
- https://site-1042629.mozfiles.com/files/1042629/vijobulez.pdf
- https://site-1043373.mozfiles.com/files/1043373/89946332803.pdf
- https://cdn.shopify.com/s/files/1/0502/9324/4069/files/40272301765.pdf
- https://cdn.shopify.com/s/files/1/0430/8529/9876/files/dijijejuvixajejar.pdf
- https://cdn.shopify.com/s/files/1/0479/1035/5110/files/19468023171.pdf
- https://cdn.shopify.com/s/files/1/0457/6237/9940/files/certified_ophthalmic_assistant_exam_review_manual_third_edition.pdf
- https://cdn.shopify.com/s/files/1/0477/6201/4364/files/quadratic_function_graph_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0434/2225/3212/files/condensing_steam_turbine.pdf
- https://cdn.shopify.com/s/files/1/0431/3029/0327/files/4262540653.pdf
- https://cdn.shopify.com/s/files/1/0437/7575/4389/files/wumezuzu.pdf
- https://cdn.shopify.com/s/files/1/0500/2572/6102/files/wovodupi.pdf
- https://cdn.shopify.com/s/files/1/0435/2180/2404/files/20650596121.pdf
- https://cdn-cms.f-static.net/uploads/4367005/normal_5f873c72defd1.pdf
- https://cdn-cms.f-static.net/uploads/4368501/normal_5f87b945819f1.pdf
- https://cdn-cms.f-static.net/uploads/4366952/normal_5f872a9582215.pdf
- https://cdn-cms.f-static.net/uploads/4366653/normal_5f8760f7da6f5.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f8725a8b6c0e.pdf
- https://uploads.strikinglycdn.com/files/36697dbb-7cfe-4b7a-8190-b8e5db0fcfdf/wegog.pdf
- https://uploads.strikinglycdn.com/files/524e3291-68aa-4ada-b6c9-47f9957f542d/45051837412.pdf
- https://uploads.strikinglycdn.com/files/afefb9d2-2542-48c7-837a-dc08b2257362/magejitadawufurazefilute.pdf
- https://uploads.strikinglycdn.com/files/3b87027e-3082-4ec2-849d-82e8bcec0fba/miruvorutetilanavit.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f873c4d2b05e.pdf
Embedded domains
- cctraff.ru
- site-1037215.mozfiles.com
- site-1039838.mozfiles.com
- site-1042629.mozfiles.com
- site-1043373.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report