SUSPICIOUS — normal_5f8718e221559.pdf
SUSPICIOUS — normal_5f8718e221559.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6f86e3327692c56a87bbf25f738ae375924ade9e2fd140c4a5a39dfc1d702562 - SHA-1:
7099dc69482561d242a5c42b0075559244d1356a - MD5:
5b4102445f42305391d57d04ba844d6b - ssdeep:
768:OgGzpDeppv4ONQb0+aOBoaELoILXfvFh4mnLnGBf8JGPx:rGFqpMGaG8mLnqf8JGPx - TLSH:
T1A0318DF35093EC8C7E8B6F0399E711AE918ED34C612AA7604588721DC47C6EE7E40A65 - Submitted as: normal_5f8718e221559.pdf
- File type: pdf · Size: 42238 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=lease+agreement+template+south+africa+pdf, https://cdn-cms.f-static.net/uploads/4365525/normal_5f870cda3fb82.pdf, https://cdn-cms.f-static.net/uploads/4366050/normal_5f870b9f052dc.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=lease+agreement+template+south+africa+pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f870cda3fb82.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_5f870b9f052dc.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f86fd00a1679.pdf
- https://cdn.shopify.com/s/files/1/0500/3146/0509/files/solutions_manual_to_accompany_time_series_analysis_with_applications_in_r_second_edition.pdf
- https://cdn.shopify.com/s/files/1/0434/3188/6998/files/16309845244.pdf
- https://site-1037283.mozfiles.com/files/1037283/fofuwulogudixipizap.pdf
- https://site-1039847.mozfiles.com/files/1039847/55467833912.pdf
- https://site-1038869.mozfiles.com/files/1038869/dajuzimuribuzokomaxapik.pdf
- https://site-1038679.mozfiles.com/files/1038679/47767313965.pdf
- https://uploads.strikinglycdn.com/files/3821fb7d-dd3d-4036-bc83-ad7bb807eaa7/bininitoguso.pdf
- https://uploads.strikinglycdn.com/files/59d4c075-9080-4162-a36c-649448b5a4c9/29843226665.pdf
- https://uploads.strikinglycdn.com/files/8e9fc9c4-d770-4cae-96dc-fba8d3ec7170/45400312613.pdf
- https://uploads.strikinglycdn.com/files/bc0f2750-e33f-456f-828b-b03a4ccad0f2/36554418455.pdf
- https://uploads.strikinglycdn.com/files/b16d10d5-6025-4932-bea3-3934baac481c/gifalubixozib.pdf
- https://uploads.strikinglycdn.com/files/06a80604-815d-4380-a926-13ea9694b5a0/56189469085.pdf
- https://uploads.strikinglycdn.com/files/481238c3-d212-4533-833e-901f2827dd85/zosaxi.pdf
- https://uploads.strikinglycdn.com/files/45967c47-076e-4e98-9904-661391709162/wegububozobexo.pdf
- https://uploads.strikinglycdn.com/files/057bbabc-8ab5-4736-a55b-ee24bad3a706/wuxasogatapadudoj.pdf
- https://uploads.strikinglycdn.com/files/1badd5bd-5ecb-4d0f-aef0-ef625bcbe0bb/begino.pdf
- https://uploads.strikinglycdn.com/files/0ac276c5-f6dc-42af-ad7a-e375237e3ffd/64780393552.pdf
- https://uploads.strikinglycdn.com/files/8eae09d8-fbce-4238-9e38-22c8d7d5a918/36383122890.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1037283.mozfiles.com
- site-1039847.mozfiles.com
- site-1038869.mozfiles.com
- site-1038679.mozfiles.com
- uploads.strikinglycdn.com
- 5.nl
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report