SUSPICIOUS — normal_5f88c28f29b00.pdf
SUSPICIOUS — normal_5f88c28f29b00.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a0ece39eebf0a6775fed4e3264bef8be46e5836c420569589f895b2f39f277d0 - SHA-1:
5a8aa85657afbd6004d3cfd3163527a0c9109a2d - MD5:
707bcb6f4dcfd2b10e3e1aadd364b797 - ssdeep:
768:SbgGzpDSpWnkK86ZxD0IIshxNMly6C0dDyt8CYTqOufwa9vMjcoWsPYU+xdP:fGFWpWnkKHnIwWNufwaKVfsxdP - TLSH:
T16A339FF311A7ED8C7A4B6B07AFAB105CA58AC34C61379750458C672CC4BC7BD6E01A64 - Submitted as: normal_5f88c28f29b00.pdf
- File type: pdf · Size: 51283 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=plangrid+for+android+download, https://uploads.strikinglycdn.com/files/f0d1c875-b217-4860-a5a2-57806ae8de20/merisabudezobeno.pdf, https://uploads.strikinglycdn.com/files/e929ef60-6a94-456c-affa-6d679b8c956f/29932867104.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=plangrid+for+android+download
- https://uploads.strikinglycdn.com/files/f0d1c875-b217-4860-a5a2-57806ae8de20/merisabudezobeno.pdf
- https://uploads.strikinglycdn.com/files/e929ef60-6a94-456c-affa-6d679b8c956f/29932867104.pdf
- https://uploads.strikinglycdn.com/files/8cc3f4dd-90d8-4569-b1aa-7786e05721fa/nazazitiboraji.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f87289c772da.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f875aac8ada2.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f875164d9422.pdf
- https://uploads.strikinglycdn.com/files/d8316c5c-c605-4c50-af7f-05d2aa7e27dc/koranemutimijusexaz.pdf
- https://uploads.strikinglycdn.com/files/5247198d-44d9-4b19-9984-5638eb156364/70459450979.pdf
- https://uploads.strikinglycdn.com/files/8b7e60e8-f8ea-42b8-bed9-8dbd3b2ed855/kiwukegoxadoperep.pdf
- https://uploads.strikinglycdn.com/files/422fc716-7230-4078-8ed8-9b2abfbcb195/juwekekadirunosowedodu.pdf
- https://duxixujojive.weebly.com/uploads/1/3/0/7/130739103/6c26f1410aadb18.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/mofep.pdf
- https://tamagokevalagir.weebly.com/uploads/1/3/0/7/130776783/8425186.pdf
- https://uploads.strikinglycdn.com/files/4a6f7bc0-2f3e-45ae-a73d-444d34a3d9fa/73281212505.pdf
- https://uploads.strikinglycdn.com/files/8978fcb0-bcce-444b-971f-5fe884f59e46/sasuwajodunexuneterug.pdf
- https://uploads.strikinglycdn.com/files/3967fc17-78de-447c-9589-b028f88a5c6a/11551810592.pdf
- https://uploads.strikinglycdn.com/files/9596b28e-9e67-4d54-86f5-9b20a4e249c3/pabelalopusilesitog.pdf
- https://cdn.shopify.com/s/files/1/0481/5867/1015/files/shower_tray_riser_kit_instructions.pdf
- https://cdn.shopify.com/s/files/1/0492/8189/2508/files/chemistry_answer_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- duxixujojive.weebly.com
- dutitujazekap.weebly.com
- guwomenod.weebly.com
- tamagokevalagir.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report