SUSPICIOUS — normal_5f8c9ee11b75d.pdf
SUSPICIOUS — normal_5f8c9ee11b75d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a51587667667769866547baf24d166033f348bb17a3ee0b0b7079c4c10ffc6e5 - SHA-1:
fffcf2e6ec45ff174d95ea8b1182a649fd144c93 - MD5:
5f33597ac6faed6f056f286b4d356afd - ssdeep:
768:cYXgGzpDupNiLKkSUh3e8oMcJ0EKHXE6uT7kqEVoHYjB7EchcrSkLxC/TMiN+6c+:sGFSpNiLKJse8o3n0hcRLxYTFN+6cijx - TLSH:
T13E339EF32097ED8D7A8B6B57ADF7015D9089C28E6026D76044882B5CD5BC6FD7E00B60 - Submitted as: normal_5f8c9ee11b75d.pdf
- File type: pdf · Size: 48203 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=cbr+reader+android+tv, https://cdn.shopify.com/s/files/1/0497/3497/5639/files/pidizarotojaxagilego.pdf, https://cdn.shopify.com/s/files/1/0498/0064/2721/files/navy_chief_garrison_cap_regulations.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.ru/123?keyword=cbr+reader+android+tv
- https://cdn.shopify.com/s/files/1/0497/3497/5639/files/pidizarotojaxagilego.pdf
- https://cdn.shopify.com/s/files/1/0498/0064/2721/files/navy_chief_garrison_cap_regulations.pdf
- https://cdn.shopify.com/s/files/1/0440/1912/2341/files/bijutasoredudewom.pdf
- https://cdn.shopify.com/s/files/1/0497/3897/3345/files/rca_universal_remote_manual_rcr414bhe.pdf
- https://cdn.shopify.com/s/files/1/0486/1132/8160/files/xovizi.pdf
- https://cdn.shopify.com/s/files/1/0437/6815/2216/files/25546342652.pdf
- https://cdn.shopify.com/s/files/1/0497/9346/6517/files/5164955367.pdf
- https://cdn.shopify.com/s/files/1/0483/0796/2018/files/jadixotilogos.pdf
- https://cdn.shopify.com/s/files/1/0440/3062/3894/files/bronco_band_songs.pdf
- https://cdn.shopify.com/s/files/1/0484/9929/4363/files/free_printable_weekly_schedule.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f8726c432062.pdf
- https://cdn-cms.f-static.net/uploads/4368488/normal_5f887bad1f9c4.pdf
- https://cdn.shopify.com/s/files/1/0431/4605/1744/files/16600985038.pdf
- https://cdn.shopify.com/s/files/1/0430/6753/9605/files/1245785612.pdf
- https://cdn-cms.f-static.net/uploads/4367912/normal_5f8a326abbd0a.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f8c402d95016.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f8897802bd9d.pdf
- https://cdn-cms.f-static.net/uploads/4369788/normal_5f87e8d1d972c.pdf
- https://cdn-cms.f-static.net/uploads/4376098/normal_5f8a3f7f4d4d1.pdf
- https://uploads.strikinglycdn.com/files/bdc4118b-3bf1-4262-b7f5-cd2d99c6a1d6/14416453489.pdf
- https://uploads.strikinglycdn.com/files/f7bffc26-26e6-4825-b49a-ec0933f3cde5/23919285541.pdf
- https://uploads.strikinglycdn.com/files/fca49957-4a27-4208-bd10-8a0f7a4e52c9/bikibijabotivujuguparamuj.pdf
- https://uploads.strikinglycdn.com/files/5f63c3c8-c7e5-4bc3-bb4b-b4024b6f49ca/18873302490.pdf
- https://uploads.strikinglycdn.com/files/8f6fa1f1-b6dd-4b00-be84-c386e40a7ed6/26730593180.pdf
Embedded domains
- ttraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report