SUSPICIOUS — normal_5f891982292b9.pdf
SUSPICIOUS — normal_5f891982292b9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
941fcf76ba3cbd00ef36804b978e40fc580ab09978a09e82bfb60417ce1726c7 - SHA-1:
0580e5d82027ced80c007ef9bc4a720b4c596d69 - MD5:
7c1c325107babf45281e0f874a98af08 - ssdeep:
768:cgGzpDqprsb2z//aIShx3MU+34oYA4++wiUMIie8qapm/BLMgOaPRuwuQFhbiQ:5GF+p+MUnoYA8Ux8qapm/BL1hPRlJqQ - TLSH:
T18632AEF79497DD4C7ACBA703ADAA1599125EE38DA173E3504988732DC0AC6BD7F00820 - Submitted as: normal_5f891982292b9.pdf
- File type: pdf · Size: 43477 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=rules+of+exponents+worksheet+doc, https://site-1048445.mozfiles.com/files/1048445/cm13_theme_engine_apk.pdf, https://site-1039510.mozfiles.com/files/1039510/wozivibepuzovedafam.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=rules+of+exponents+worksheet+doc
- https://site-1048445.mozfiles.com/files/1048445/cm13_theme_engine_apk.pdf
- https://site-1039510.mozfiles.com/files/1039510/wozivibepuzovedafam.pdf
- https://site-1042767.mozfiles.com/files/1042767/nafupipajufu.pdf
- https://cdn.shopify.com/s/files/1/0440/2076/0741/files/clairol_foot_fixer_instructions.pdf
- https://cdn.shopify.com/s/files/1/0498/0293/6477/files/papa_johns_original_crust.pdf
- https://cdn.shopify.com/s/files/1/0484/7927/3115/files/78966236696.pdf
- https://cdn.shopify.com/s/files/1/0482/2899/1130/files/29085881763.pdf
- https://cdn.shopify.com/s/files/1/0468/0119/1063/files/kovilobiwoma.pdf
- https://cdn-cms.f-static.net/uploads/4374362/normal_5f89072a454b6.pdf
- https://cdn-cms.f-static.net/uploads/4368747/normal_5f88fd666c67d.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87019214543.pdf
- https://cdn-cms.f-static.net/uploads/4369141/normal_5f87d50bea4e0.pdf
- https://uploads.strikinglycdn.com/files/b2c5437b-adf2-4381-b183-471288d2c56e/suzujudozanokek.pdf
- https://uploads.strikinglycdn.com/files/b5857d1d-c5f2-43db-b6a9-4653d3635e17/sumijawukibezasud.pdf
- https://uploads.strikinglycdn.com/files/2395cae8-dbac-49fd-8560-073cbb52235a/69100822243.pdf
- https://uploads.strikinglycdn.com/files/aca23532-11db-4f99-9d60-dfbb26528f3d/82307682597.pdf
- https://site-1040871.mozfiles.com/files/1040871/301672830.pdf
- https://site-1038378.mozfiles.com/files/1038378/28434305527.pdf
- https://site-1042627.mozfiles.com/files/1042627/mazidiribitipuvogaga.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/kibozazogarul-serupele.pdf
- https://fifowekuvepu.weebly.com/uploads/1/3/0/7/130776735/9f59c9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- site-1048445.mozfiles.com
- site-1039510.mozfiles.com
- site-1042767.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1040871.mozfiles.com
- site-1038378.mozfiles.com
- site-1042627.mozfiles.com
- vimiwegom.weebly.com
- fifowekuvepu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report