SUSPICIOUS — normal_5f874a5f3369f.pdf
SUSPICIOUS — normal_5f874a5f3369f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9769ef31e8169705126fd9023406f46850622b9380dd3a134cb57559ccb2ed29 - SHA-1:
dea9eed6a10410df0af6367388aa31f2a6928042 - MD5:
4f23bd7e4d362da9ff3d3741e8b56420 - ssdeep:
768:jgGzpDipo/UTGKaKJyfewj41eWuJD3wd:cGF2pCUnJyGw81eWQD3wd - TLSH:
T1DC306CF314A7ED4CBE87AB43ADE711996089C388B236E7904488772DC4BC5AD7F50960 - Submitted as: normal_5f874a5f3369f.pdf
- File type: pdf · Size: 37526 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=hora+cero+ernesto+cardenal+pdf, https://uploads.strikinglycdn.com/files/569856a1-b83c-40ac-b7e1-4748591949bc/fiwow.pdf, https://uploads.strikinglycdn.com/files/5f21d539-dc61-4454-8b02-263816c59592/fomadazebikuxit.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=hora+cero+ernesto+cardenal+pdf
- https://uploads.strikinglycdn.com/files/569856a1-b83c-40ac-b7e1-4748591949bc/fiwow.pdf
- https://uploads.strikinglycdn.com/files/5f21d539-dc61-4454-8b02-263816c59592/fomadazebikuxit.pdf
- https://uploads.strikinglycdn.com/files/0d71ea04-cffb-4061-94cb-646b47fa90c5/vovero.pdf
- https://uploads.strikinglycdn.com/files/dfefd78d-9dd6-4e83-beda-a53001550496/29217048248.pdf
- https://uploads.strikinglycdn.com/files/fd00d228-73f7-4424-8f36-9e7fdad5bd34/18715472513.pdf
- https://site-1039215.mozfiles.com/files/1039215/71908106714.pdf
- https://site-1036988.mozfiles.com/files/1036988/73532007784.pdf
- https://site-1040984.mozfiles.com/files/1040984/18793385417.pdf
- https://site-1038427.mozfiles.com/files/1038427/19826602797.pdf
- https://site-1042607.mozfiles.com/files/1042607/nerukabubikekikobuguzaw.pdf
- https://site-1041084.mozfiles.com/files/1041084/6665414725.pdf
- https://site-1042585.mozfiles.com/files/1042585/42042243482.pdf
- https://site-1043405.mozfiles.com/files/1043405/gijabes.pdf
- https://site-1044245.mozfiles.com/files/1044245/20559669549.pdf
- https://site-1042025.mozfiles.com/files/1042025/xejusuwak.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/bademasotud-muwoxob-keruluzaraji-tiwifozexomepog.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/wizovaderu.pdf
- https://uploads.strikinglycdn.com/files/3678d20c-8f36-43c1-8663-6d6078792cbb/35038252739.pdf
- https://uploads.strikinglycdn.com/files/aaa50120-adef-4255-bff7-7c1b20f1b684/beletipekigu.pdf
- https://uploads.strikinglycdn.com/files/447db31d-01e0-47d8-a3d3-132290d5c8d2/9415725442.pdf
- https://dagigokes.weebly.com/uploads/1/3/0/7/130739756/5e20c36439039.pdf
- https://gevafitasib.weebly.com/uploads/1/3/1/3/131380901/e27909d0be.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/3722212.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/9b53ec72f.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1039215.mozfiles.com
- site-1036988.mozfiles.com
- site-1040984.mozfiles.com
- site-1038427.mozfiles.com
- site-1042607.mozfiles.com
- site-1041084.mozfiles.com
- site-1042585.mozfiles.com
- site-1043405.mozfiles.com
- site-1044245.mozfiles.com
- site-1042025.mozfiles.com
- xojerajap.weebly.com
- besiwalufeg.weebly.com
- dagigokes.weebly.com
- gevafitasib.weebly.com
- jawasolasazilem.weebly.com
- mogilifus.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report