SUSPICIOUS — normal_5f8719fa703ce.pdf
SUSPICIOUS — normal_5f8719fa703ce.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a88b4da81cd9646f047f5c913e9056d93a4b5ff15dba0be02036b878ec7e08f8 - SHA-1:
d02e2f663eb02e454ea64108f1ecdf3926fa5bcd - MD5:
7e9caf56c671a913caec7a688208547c - ssdeep:
768:ygGzpDwpx6P5R2b+gv3SSekJzrTnhel4P8Gj8jSuRQd0JwmDAXfkY:vGFspvz64Pj8c0JcfkY - TLSH:
T18D326DF350A7ED8CB68FAB43AEA6059D644AD3487132D7A00588362DD4BC9FD3F00665 - Submitted as: normal_5f8719fa703ce.pdf
- File type: pdf · Size: 46541 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=tecnica+de+hematoxilina+y+eosina+pdf, https://uploads.strikinglycdn.com/files/37c1f8a2-5266-4adb-809b-f9aedde4782e/xazerotugox.pdf, https://uploads.strikinglycdn.com/files/44be60f3-0094-4caf-9472-d2d3952cfd2d/28220625843.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=tecnica+de+hematoxilina+y+eosina+pdf
- https://uploads.strikinglycdn.com/files/37c1f8a2-5266-4adb-809b-f9aedde4782e/xazerotugox.pdf
- https://uploads.strikinglycdn.com/files/44be60f3-0094-4caf-9472-d2d3952cfd2d/28220625843.pdf
- https://uploads.strikinglycdn.com/files/59ddd65f-0b55-4916-880d-71cc25c200af/vutusajafepos.pdf
- https://uploads.strikinglycdn.com/files/43d95c42-82b4-4133-ad01-e1889c4667c8/puwamoxovitaladutoxejijo.pdf
- https://uploads.strikinglycdn.com/files/1d70a7b2-5472-4d2e-9876-509826c8f16d/ranugaxurobewiwufo.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f87148b45edd.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f8711f3b028a.pdf
- https://cdn-cms.f-static.net/uploads/4365598/normal_5f871929828d1.pdf
- https://uploads.strikinglycdn.com/files/e9097036-da3f-4c3b-8aad-2cf3c949b2da/vowakuvisujol.pdf
- https://uploads.strikinglycdn.com/files/822d98a3-d4ec-42ae-b2c3-878797e93071/larus.pdf
- https://uploads.strikinglycdn.com/files/6f73e557-b2ca-4101-a7db-55b19ffc3165/ruderovusitunoxepisi.pdf
- https://uploads.strikinglycdn.com/files/48f3ae99-d7fe-4175-8473-6ef4591a966f/27491903077.pdf
- https://cdn.shopify.com/s/files/1/0437/4318/2999/files/xazudem.pdf
- https://cdn.shopify.com/s/files/1/0266/9451/6907/files/66458652789.pdf
- https://cdn.shopify.com/s/files/1/0440/2295/6197/files/xanowifadusopuvez.pdf
- https://cdn.shopify.com/s/files/1/0481/7800/4135/files/98308561205.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f870dc82dc06.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f86f3f543087.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f86f4529e088.pdf
- https://cdn-cms.f-static.net/uploads/4366401/normal_5f871688edf7c.pdf
- https://site-1042677.mozfiles.com/files/1042677/45084787657.pdf
- https://site-1041927.mozfiles.com/files/1041927/xalosatibokezoxuvebonora.pdf
- https://site-1037205.mozfiles.com/files/1037205/zelaf.pdf
- https://site-1048473.mozfiles.com/files/1048473/24039696684.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1042677.mozfiles.com
- site-1041927.mozfiles.com
- site-1037205.mozfiles.com
- site-1048473.mozfiles.com
- site-1040177.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report