SUSPICIOUS — normal_5f8b331183f56.pdf
SUSPICIOUS — normal_5f8b331183f56.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
76fd42f5ba5a227a87a62a7038bb5de37ce59b55f47dfcf4f1400c1a175bd11c - SHA-1:
f5d9596186b4e9e6181dcfb4ffb7e8120391a45b - MD5:
04830fdf30a56ced18fd70492eefd928 - ssdeep:
768:n5gGzpDj3pfbji2HrVXoLibITCdYCyKJkT6jcTMdWqKdMZO35X9daOSgl8pJ54OF:6GFnpTUHukT6jfXKdp35X9EOSgl8pJx1 - TLSH:
T19C327DF350A7ED4C7A8F5F43AD9711ADA14AC38DA027965004CCB27CD4BCAED6E10A61 - Submitted as: normal_5f8b331183f56.pdf
- File type: pdf · Size: 43400 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=ds+emulator+for+android+6+apk, https://biwugina.weebly.com/uploads/1/3/1/1/131163984/7320533.pdf, https://vefoxetewezelir.weebly.com/uploads/1/3/1/4/131483279/f12a8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=ds+emulator+for+android+6+apk
- https://biwugina.weebly.com/uploads/1/3/1/1/131163984/7320533.pdf
- https://vefoxetewezelir.weebly.com/uploads/1/3/1/4/131483279/f12a8.pdf
- https://gukaguse.weebly.com/uploads/1/3/1/3/131398473/lixoxasutanurij.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kadupe_ripovu_jozovagazemewe.pdf
- https://gikoberi.weebly.com/uploads/1/3/0/9/130969260/8a0409a771f9f2.pdf
- https://uploads.strikinglycdn.com/files/aca5970a-03cb-46b7-910b-cf6367d5634c/dutipezabopoxunubun.pdf
- https://cdn.shopify.com/s/files/1/0477/2193/9100/files/clovis_east_baseball_maxpreps.pdf
- https://cdn.shopify.com/s/files/1/0266/9346/8347/files/51387135716.pdf
- https://cdn.shopify.com/s/files/1/0435/3005/9927/files/wells_report.pdf
- https://cdn.shopify.com/s/files/1/0440/4012/6614/files/opinion_writing_prompts_2nd_grade.pdf
- https://cdn.shopify.com/s/files/1/0433/3341/9160/files/11788948800.pdf
- https://cdn.shopify.com/s/files/1/0431/7940/9568/files/american_technology_services_glassdoor.pdf
- https://cdn.shopify.com/s/files/1/0481/3747/0115/files/livre_auxiliaire_de_puriculture_2020.pdf
- https://cdn.shopify.com/s/files/1/0477/1489/3980/files/warframe_ability_efficiency.pdf
- https://cdn.shopify.com/s/files/1/0434/7871/2472/files/22936887458.pdf
- https://pisanofinupu.weebly.com/uploads/1/3/1/4/131437881/jijawotazukugos.pdf
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/dikumoj.pdf
- https://fuvipizewovotat.weebly.com/uploads/1/3/1/0/131069886/8206116.pdf
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f88d771cbd2b.pdf
- https://cdn-cms.f-static.net/uploads/4373788/normal_5f89d7955ce25.pdf
- https://cdn-cms.f-static.net/uploads/4369774/normal_5f889f8a12b27.pdf
- https://cdn-cms.f-static.net/uploads/4369935/normal_5f87e0f9ed9d0.pdf
- https://cdn-cms.f-static.net/uploads/4366995/normal_5f8819876b0c1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- biwugina.weebly.com
- vefoxetewezelir.weebly.com
- gukaguse.weebly.com
- gimejexoxixaza.weebly.com
- gikoberi.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- pisanofinupu.weebly.com
- sokuvotaboraj.weebly.com
- fuvipizewovotat.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report