SUSPICIOUS — normal_5f88bc8ac0084.pdf
SUSPICIOUS — normal_5f88bc8ac0084.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
86427c1523adbfc6c8b83abf87f8d2a2235b9653a92318ab0ad8e69e137d7e6f - SHA-1:
f343bd83789644df10389df40d718752972db391 - MD5:
e5e3cc014886b6217cee05ef62f9243c - ssdeep:
768:zgGzpDmpgBxVYXmBntAVbzgYTDGFIhuViUHmbbQUTB18YNBuZm33oWpuh3Ctx:MGFap8YXmtQFNMZm33oWpUytx - TLSH:
T160328CF35067ED8C7AC79B13ADEB255E9049D34C9072EB604998272CC9BC6BE2F10910 - Submitted as: normal_5f88bc8ac0084.pdf
- File type: pdf · Size: 46190 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=geometry+dash+full+version+apk+download, https://cdn.shopify.com/s/files/1/0498/2915/0875/files/64335933544.pdf, https://cdn.shopify.com/s/files/1/0437/0920/2597/files/lunijawupox.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=geometry+dash+full+version+apk+download
- https://cdn.shopify.com/s/files/1/0498/2915/0875/files/64335933544.pdf
- https://cdn.shopify.com/s/files/1/0437/0920/2597/files/lunijawupox.pdf
- https://cdn.shopify.com/s/files/1/0499/7283/8564/files/lujukirofuzajogebukibafu.pdf
- https://cdn.shopify.com/s/files/1/0266/9576/2096/files/edge_interactive_practice_book_answers_unit_5.pdf
- https://cdn.shopify.com/s/files/1/0501/1505/1685/files/64790189818.pdf
- https://cdn.shopify.com/s/files/1/0434/7471/4784/files/27660267382.pdf
- https://cdn.shopify.com/s/files/1/0501/6649/7440/files/false_memory_syndrome_foundation.pdf
- https://cdn.shopify.com/s/files/1/0500/6298/3331/files/xidimawubiravufu.pdf
- https://cdn.shopify.com/s/files/1/0484/4647/2342/files/mcgraw_hill_biology_4th_edition.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/tomenodu.pdf
- https://fobewesepujub.weebly.com/uploads/1/3/2/3/132303403/8891251.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/debizikirapanas.pdf
- https://site-1044202.mozfiles.com/files/1044202/dekebagefakowixuju.pdf
- https://site-1043332.mozfiles.com/files/1043332/43915679701.pdf
- https://site-1038539.mozfiles.com/files/1038539/zexixubaxegewewaz.pdf
- https://site-1038831.mozfiles.com/files/1038831/61140004898.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f870920c8535.pdf
- https://cdn-cms.f-static.net/uploads/4370059/normal_5f88bc86411c8.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f8701147343b.pdf
- https://cdn-cms.f-static.net/uploads/4368985/normal_5f88b8dfdd674.pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f8704a7af8f6.pdf
- https://cdn.shopify.com/s/files/1/0496/0600/0789/files/lesuvisekuzapiw.pdf
- https://cdn.shopify.com/s/files/1/0431/8792/9249/files/decrypt_software_for_android.pdf
- https://cdn.shopify.com/s/files/1/0440/7794/0886/files/wyoming_medicaid_provider_manual.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- jezaxegare.weebly.com
- fobewesepujub.weebly.com
- vuxozajuje.weebly.com
- site-1044202.mozfiles.com
- site-1043332.mozfiles.com
- site-1038539.mozfiles.com
- site-1038831.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report