SUSPICIOUS — normal_5f88381e7e824.pdf
SUSPICIOUS — normal_5f88381e7e824.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
8e8382a611b79eff4195958909d5d2ab72550b5fb3db959f9269a8971479176a - SHA-1:
c6df93032ddeb5936fc745bf31fce3c0617d3b23 - MD5:
ca38bb1aadb0f506a977269bc2ac73c2 - ssdeep:
768:PgGzpDlpbO6NderiyO6SEB9ngL1wxzjlLhI+TAXgtiNOlj:4GFZpp6S29ngLGXlLhIKATNOlj - TLSH:
T1C4329EF35497EC8D7A8B6B43ACFB005A508AC30DA126D7605498B73DE4BC6BD7E10960 - Submitted as: normal_5f88381e7e824.pdf
- File type: pdf · Size: 44130 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=holiday+gift+guide+2020, https://uploads.strikinglycdn.com/files/4f6a4731-c012-44c6-8edd-ffa68d3d01e3/jarajavuxuwebiwunanut.pdf, https://uploads.strikinglycdn.com/files/8bbe4f44-8ef7-4d6e-93ca-ed527eb079f4/98574385427.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=holiday+gift+guide+2020
- https://uploads.strikinglycdn.com/files/4f6a4731-c012-44c6-8edd-ffa68d3d01e3/jarajavuxuwebiwunanut.pdf
- https://uploads.strikinglycdn.com/files/8bbe4f44-8ef7-4d6e-93ca-ed527eb079f4/98574385427.pdf
- https://uploads.strikinglycdn.com/files/4f8be112-08a7-4282-b2a9-fdf7e98f7631/risili.pdf
- https://uploads.strikinglycdn.com/files/1349895a-b561-4865-a8a9-817bbad20403/56807337087.pdf
- https://cdn.shopify.com/s/files/1/0482/2899/1130/files/14598654907.pdf
- https://cdn.shopify.com/s/files/1/0483/0789/6482/files/kevotitapif.pdf
- https://cdn.shopify.com/s/files/1/0430/6223/1201/files/gawamanenum.pdf
- https://cdn.shopify.com/s/files/1/0496/6190/3005/files/xeperorapasulorizob.pdf
- https://pukotegifo.weebly.com/uploads/1/3/0/8/130874060/vusize-refovun-nisinatuvetom-vijutemefinemo.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/6813382.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/3cb113af6.pdf
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/salopuro-dawibibidir-rebofekoninufam.pdf
- https://site-1042983.mozfiles.com/files/1042983/sigawanokutotefaf.pdf
- https://site-1039935.mozfiles.com/files/1039935/50148710606.pdf
- https://site-1044186.mozfiles.com/files/1044186/andy_weir_el_huevo.pdf
- https://site-1037207.mozfiles.com/files/1037207/80256882666.pdf
- https://site-1039285.mozfiles.com/files/1039285/34378255582.pdf
- https://site-1042504.mozfiles.com/files/1042504/jijejomi.pdf
- https://site-1039892.mozfiles.com/files/1039892/sikunub.pdf
- https://site-1038690.mozfiles.com/files/1038690/tibaze.pdf
- https://site-1042450.mozfiles.com/files/1042450/1355558290.pdf
- https://cdn.shopify.com/s/files/1/0486/0870/6725/files/rainbow_six_siege_burnt_horizon_release_date_ps4.pdf
- https://cdn.shopify.com/s/files/1/0437/6766/0706/files/talking_tom_apk_mod.pdf
- https://cdn.shopify.com/s/files/1/0430/8841/2836/files/hauppauge_wintv_7_serial_number.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- pukotegifo.weebly.com
- sepikupi.weebly.com
- keniwuki.weebly.com
- medizagokitoni.weebly.com
- site-1042983.mozfiles.com
- site-1039935.mozfiles.com
- site-1044186.mozfiles.com
- site-1037207.mozfiles.com
- site-1039285.mozfiles.com
- site-1042504.mozfiles.com
- site-1039892.mozfiles.com
- site-1038690.mozfiles.com
- site-1042450.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report