SUSPICIOUS — normal_5f870af2bdb56.pdf
SUSPICIOUS — normal_5f870af2bdb56.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6ef9cb76455105de83718b5e012f41d40410106b727da117ed98d095d3778d04 - SHA-1:
cbf7ebda6533f99ae98edabf62e2ccfa87c532c4 - MD5:
26bb467281790275e5e54570b719ca93 - ssdeep:
768:tgGzpDapjCMbCHRZCl3c4Petcp7/OCUg87dqAQQX1FPMGWgDc+JgSop6IB:OGFmpjCMwo/mbkAyGWpiop6IB - TLSH:
T19F328CF710B3CD8C79879B53AEFA2449A04EE3486172DBA0448C676DD4BC6BC7E01961 - Submitted as: normal_5f870af2bdb56.pdf
- File type: pdf · Size: 46004 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=fire+detection+sensor+pdf, https://uploads.strikinglycdn.com/files/b8cc4fa6-37df-4daa-931e-20706cd4eaf8/mitidileparinamazufo.pdf, https://uploads.strikinglycdn.com/files/32fb87f7-87b6-4b50-b792-b014d1fd606f/3856480883.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=fire+detection+sensor+pdf
- https://uploads.strikinglycdn.com/files/b8cc4fa6-37df-4daa-931e-20706cd4eaf8/mitidileparinamazufo.pdf
- https://uploads.strikinglycdn.com/files/32fb87f7-87b6-4b50-b792-b014d1fd606f/3856480883.pdf
- https://uploads.strikinglycdn.com/files/500ce642-dbc1-4b3a-aab8-69fcf242697e/laranutitopi.pdf
- https://uploads.strikinglycdn.com/files/4488fb84-e0c0-4312-adc9-80d21eb99e3f/pewajewekebusawuba.pdf
- https://uploads.strikinglycdn.com/files/960709e4-1536-4e6a-aabb-636763ca313f/nifosaxitabebunimofamap.pdf
- https://uploads.strikinglycdn.com/files/baab222c-0e27-467b-b35c-af24444dee47/toramumiguvedodika.pdf
- https://uploads.strikinglycdn.com/files/7915665c-6f8e-46ab-a1f6-d76d5fb706d2/69379269287.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f86fb08daf31.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f87068315723.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f87038fa98a5.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f86fa89daad5.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f86fa16347a3.pdf
- https://uploads.strikinglycdn.com/files/bb4dc0b6-49bc-4b4c-a0f0-5303693dea4e/veborito.pdf
- https://uploads.strikinglycdn.com/files/a7e578e5-6426-43d8-a6fd-8d9b02b73055/baniniravasididogoduru.pdf
- https://uploads.strikinglycdn.com/files/37cd5138-8754-40d2-8ce3-3dc2b3e0caa1/sesofa.pdf
- https://uploads.strikinglycdn.com/files/61945d57-e97b-4154-bc28-2ab75cd31d94/49743738214.pdf
- https://uploads.strikinglycdn.com/files/622d2cbf-6957-46c8-a5ec-83c3d9e91519/72390042465.pdf
- https://uploads.strikinglycdn.com/files/eec655f9-178c-4223-a015-07054684b055/tidikuseruxiwumimozito.pdf
- https://uploads.strikinglycdn.com/files/e3b197fc-be64-4faa-a4ae-e89d267d7fa8/87063368471.pdf
- https://uploads.strikinglycdn.com/files/86eac23c-ffff-47c1-85a3-4d4c3c4ca3d3/29672373845.pdf
- https://cdn.shopify.com/s/files/1/0431/0397/7634/files/78144801174.pdf
- https://cdn.shopify.com/s/files/1/0437/9970/7810/files/98654296618.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report