SUSPICIOUS — normal_5f877570cb997.pdf
SUSPICIOUS — normal_5f877570cb997.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a915d4b39c5b88b9103d7d482984d9b1710f47e88568c25768e5e092dce6a969 - SHA-1:
b807f57d3b8e530c59ebd9d8a792ea4438fbfaa4 - MD5:
ce3cb86addbc2c6aace849d4af6e2f58 - ssdeep:
768:ONgGzpD1piCaHYVZ0jTTSgJR0WOG6VXZHmc/bYbjVdKg1Xs1JbgVMv3YI1fdNbNQ:BGFBpi+jQzKgB4Jbg6v3X1FNRAjxyE - TLSH:
T142328EF35093FD4C7A8AAB039DAB01A9A54ACB8D5133D390498C276CD0BCAFD7E50951 - Submitted as: normal_5f877570cb997.pdf
- File type: pdf · Size: 45665 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=download+apk+data+bully+lite+android, https://cdn-cms.f-static.net/uploads/4366041/normal_5f875a9416153.pdf, https://cdn-cms.f-static.net/uploads/4366008/normal_5f87747a7f628.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=download+apk+data+bully+lite+android
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f875a9416153.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f87747a7f628.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f876edf7cc59.pdf
- https://cdn.shopify.com/s/files/1/0496/6711/3117/files/a_beautiful_wedding_download.pdf
- https://cdn.shopify.com/s/files/1/0483/3709/2771/files/kingdom_hearts_3_lucky_strike_stack.pdf
- https://cdn.shopify.com/s/files/1/0501/6571/1013/files/12743903897.pdf
- https://cdn.shopify.com/s/files/1/0497/8016/2721/files/wadikuwakekepo.pdf
- https://uploads.strikinglycdn.com/files/ea372114-ed26-4e67-84b3-806c7945d344/filaxen.pdf
- https://uploads.strikinglycdn.com/files/34c44645-bdce-43a3-86cb-f220c33cc03b/zepuwiwamifulugavuba.pdf
- https://uploads.strikinglycdn.com/files/2344a5ca-bddf-468d-9723-66b730062ec0/xedutebuloli.pdf
- https://uploads.strikinglycdn.com/files/322b500c-4a85-40e0-8c65-2e624222324c/68013021761.pdf
- https://uploads.strikinglycdn.com/files/60d67cfc-8cf6-490e-88eb-70a39a5584f7/sagifu.pdf
- https://cdn.shopify.com/s/files/1/0483/5780/2137/files/90514070331.pdf
- https://cdn.shopify.com/s/files/1/0481/8170/6919/files/plans_to_make_a_shooting_bench.pdf
- https://cdn.shopify.com/s/files/1/0458/0881/2198/files/cordless_snow_shovel_canadian_tire.pdf
- https://cdn.shopify.com/s/files/1/0482/6968/8994/files/ravoseguwobemotadidod.pdf
- https://cdn.shopify.com/s/files/1/0459/8874/1282/files/skinerals_self_tanner_ewg.pdf
- https://cdn.shopify.com/s/files/1/0499/2915/8824/files/26611064528.pdf
- https://cdn.shopify.com/s/files/1/0427/5883/2294/files/niagara_fire_wire.pdf
- https://cdn.shopify.com/s/files/1/0432/0378/8959/files/fiduzuzi.pdf
- https://cdn-cms.f-static.net/uploads/4367952/normal_5f876e15ac841.pdf
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f8771eb5313a.pdf
- https://cdn-cms.f-static.net/uploads/4365552/normal_5f873ce5736b7.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f8722f5df299.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report