SUSPICIOUS — normal_5f876328e76d3.pdf
SUSPICIOUS — normal_5f876328e76d3.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
816abfbdb2f1fedf665d3fe76cd498fca8f7b3fa98fdcd72ba0db9f8175fac28 - SHA-1:
0b6b7480b5210f943eaf447c24a8a71d67717b33 - MD5:
87c8bdf3c2b66a1492d05153a76f54fd - ssdeep:
768:fgGzpDmenuHxied+ts42FTkjS791Pp/L+vZEt5tTGeB8cpkCd/O68HxTOGkFzy:oGFaeW8ed+uL+vyt5tTRBvP9O68RTOGt - TLSH:
T1D9328DF35097ED8C7B8F9B03AEAB01A9608AD7895136D7A01588276CC97C6FD7F10610 - Submitted as: normal_5f876328e76d3.pdf
- File type: pdf · Size: 46462 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=nothing+but+the+truth+pdf+free+download, https://cdn.shopify.com/s/files/1/0481/0509/5331/files/17865832226.pdf, https://cdn.shopify.com/s/files/1/0484/4627/5752/files/38318597184.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=nothing+but+the+truth+pdf+free+download
- https://cdn.shopify.com/s/files/1/0481/0509/5331/files/17865832226.pdf
- https://cdn.shopify.com/s/files/1/0484/4627/5752/files/38318597184.pdf
- https://cdn.shopify.com/s/files/1/0486/0788/7518/files/olive_vista_middle_school.pdf
- https://cdn.shopify.com/s/files/1/0502/9406/3269/files/head_soccer_games.pdf
- https://cdn.shopify.com/s/files/1/0429/7801/7443/files/smooth_muscle_histology_notes.pdf
- https://cdn.shopify.com/s/files/1/0432/4016/1435/files/xetumado.pdf
- https://cdn.shopify.com/s/files/1/0432/8371/0108/files/houston_tx_craigslist_farm_and_garden.pdf
- https://cdn.shopify.com/s/files/1/0480/6534/7748/files/megasajisetelipanuseba.pdf
- https://cdn.shopify.com/s/files/1/0494/4491/3311/files/55418250766.pdf
- https://site-1037182.mozfiles.com/files/1037182/lezadekake.pdf
- https://site-1043375.mozfiles.com/files/1043375/13963894156.pdf
- https://site-1041690.mozfiles.com/files/1041690/bafetabenepadinub.pdf
- https://site-1040327.mozfiles.com/files/1040327/21405326699.pdf
- https://uploads.strikinglycdn.com/files/051e6adf-2f59-46be-9234-0f8b5514415f/safajone.pdf
- https://uploads.strikinglycdn.com/files/2da6af3e-ee0c-46d7-a9a9-2839b112087c/46704006052.pdf
- https://uploads.strikinglycdn.com/files/0285da86-b270-472b-bf98-2849b8f935d8/lagemipu.pdf
- https://uploads.strikinglycdn.com/files/d76ff5d1-ccdf-49c8-b26d-ffebad8602b3/juvelisu.pdf
- https://uploads.strikinglycdn.com/files/826afb1f-14ad-45d4-b73e-57f82ff69d36/webakunetibek.pdf
- https://cdn-cms.f-static.net/uploads/4366047/normal_5f872f56d9ce6.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f87085c2f506.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f8718b9b0867.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f8704ed7ba40.pdf
- https://site-1042767.mozfiles.com/files/1042767/bevoxijodowalorufira.pdf
- https://site-1040379.mozfiles.com/files/1040379/luputudowiz.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1037182.mozfiles.com
- site-1043375.mozfiles.com
- site-1041690.mozfiles.com
- site-1040327.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1042767.mozfiles.com
- site-1040379.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report