SUSPICIOUS — normal_5f88ed37810ff.pdf
SUSPICIOUS — normal_5f88ed37810ff.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
869a5fb728a828600aa510c86d8bafe0b47c356abe407f97e3d2fd7cba7eb0e9 - SHA-1:
7a9f5348b42ed847e7cae05a27af9f8dbb56584b - MD5:
3a6249a9960def5a988d3b80a1e79bc6 - ssdeep:
1536:7GFoesoxRw8HrfHGpjnZBtjFwF+GlR/G:aFoeVvqjnfMF+GlM - TLSH:
T1AF34AFF36097ED8D768BEB03AEAA009D6506D68C6136979005CD777CC07CAFD6E10A21 - Submitted as: normal_5f88ed37810ff.pdf
- File type: pdf · Size: 52532 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=exploding+kittens+card+game+instructions, https://site-1042360.mozfiles.com/files/1042360/57260096687.pdf, https://site-1040513.mozfiles.com/files/1040513/worksheet_balancing_equations_chapter_10.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=exploding+kittens+card+game+instructions
- https://site-1042360.mozfiles.com/files/1042360/57260096687.pdf
- https://site-1040513.mozfiles.com/files/1040513/worksheet_balancing_equations_chapter_10.pdf
- https://site-1043876.mozfiles.com/files/1043876/zazikotorupazojamimes.pdf
- https://uploads.strikinglycdn.com/files/a8dce123-57f2-4cc5-b8ad-f8d7b3a0dc8b/jugepuwajonanopefisowo.pdf
- https://uploads.strikinglycdn.com/files/a18386ef-7d58-432d-88bb-b87b35c5c76f/fulezisukegujiw.pdf
- https://uploads.strikinglycdn.com/files/80868538-7c3f-469e-92dd-44dd05062d31/vuzaxexubetabewigoxobu.pdf
- https://uploads.strikinglycdn.com/files/65474bc6-359f-4063-93a8-a3bef360922a/81294401985.pdf
- https://uploads.strikinglycdn.com/files/69972315-b86e-4af4-b0c2-e282e084cb57/57409618229.pdf
- https://uploads.strikinglycdn.com/files/6b8a0fcd-d334-413d-b256-794f6da05a25/58633337547.pdf
- https://uploads.strikinglycdn.com/files/85aeabac-36fd-4d39-8bac-56942e4baaf5/38761668006.pdf
- https://cdn-cms.f-static.net/uploads/4372354/normal_5f88c088898ce.pdf
- https://cdn-cms.f-static.net/uploads/4373008/normal_5f88ab1c000ec.pdf
- https://buximinolid.weebly.com/uploads/1/3/1/3/131381316/pokivipikog_kajotora_toguki_bixawoxi.pdf
- https://bebamewikirebu.weebly.com/uploads/1/3/0/8/130874540/fewipatu_bixakidinonuxu.pdf
- https://cdn.shopify.com/s/files/1/0496/6344/3101/files/jovefovugoles.pdf
- https://cdn.shopify.com/s/files/1/0481/3884/6359/files/60869831712.pdf
- https://cdn.shopify.com/s/files/1/0488/1229/4309/files/zuzasalopegamovip.pdf
- https://cdn.shopify.com/s/files/1/0479/6347/2028/files/the_meek_shall_inherit_the_earth_bible_hub.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1042360.mozfiles.com
- site-1040513.mozfiles.com
- site-1043876.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- buximinolid.weebly.com
- bebamewikirebu.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report