SUSPICIOUS — normal_5f88a9c5d8a69.pdf
SUSPICIOUS — normal_5f88a9c5d8a69.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
aafbb1945fe516044d1fd4ec4c3a3eaa1b6c4a3ddf95c0b58e33b9507dd7d57d - SHA-1:
c1968c2f7bd88c30a597c94ee5df90c40569131a - MD5:
a57aaa3b2786b64366143a6131e00909 - ssdeep:
768:VgGzpDapcKL6L6vkh0grjG/896KobmAGMV1ts0JaHyrW/RW1iJmvIkAgKM1:GGFWpT6L54Kk8Mnts0JaK+xgKM1 - TLSH:
T1BD337DF35197DC8C7AC7AB537AEA1559904BDB886133DA6448CC272CC4BC3BD2E10A61 - Submitted as: normal_5f88a9c5d8a69.pdf
- File type: pdf · Size: 49409 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=2020+chevy+cruze+1.4+turbo+owners+manual, https://uploads.strikinglycdn.com/files/b1ec1876-ab50-4856-b328-e60bc488ca4a/wuwipotujofiwazepim.pdf, https://uploads.strikinglycdn.com/files/5000fff9-8bcb-406a-9775-d589ff1bf219/xizerenukuparobofawija.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=2020+chevy+cruze+1.4+turbo+owners+manual
- https://uploads.strikinglycdn.com/files/b1ec1876-ab50-4856-b328-e60bc488ca4a/wuwipotujofiwazepim.pdf
- https://uploads.strikinglycdn.com/files/5000fff9-8bcb-406a-9775-d589ff1bf219/xizerenukuparobofawija.pdf
- https://uploads.strikinglycdn.com/files/2ce8e978-dc27-4b75-8847-410c7b90e7ad/juvepelemusini.pdf
- https://uploads.strikinglycdn.com/files/86f25346-c218-4468-9304-380cede1487b/16633522539.pdf
- https://cdn-cms.f-static.net/uploads/4368950/normal_5f889627e3bc7.pdf
- https://uploads.strikinglycdn.com/files/fa4f276d-7377-4d35-b7c5-42ae94ab98b8/bapolabuzegofabosukepa.pdf
- https://uploads.strikinglycdn.com/files/0c44260c-e581-4baa-a9f4-c1e1638bdaeb/nodepuf.pdf
- https://uploads.strikinglycdn.com/files/e7246f83-7b39-489a-9d1b-272e20929179/91572676813.pdf
- https://uploads.strikinglycdn.com/files/e463f476-6dde-49f3-92cb-60c43f4bf6ae/13245968297.pdf
- https://uploads.strikinglycdn.com/files/7df411d9-d1d9-424b-9fbc-55d9c8cd4c69/65289482605.pdf
- https://cdn-cms.f-static.net/uploads/4366647/normal_5f882e4668276.pdf
- https://cdn-cms.f-static.net/uploads/4367920/normal_5f8763c0e3e95.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/bizerokiva.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/jixoxararena.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/18ad995.pdf
- https://cdn.shopify.com/s/files/1/0500/4037/3398/files/50697289539.pdf
- https://cdn.shopify.com/s/files/1/0478/6651/1526/files/suvasojo.pdf
- https://cdn.shopify.com/s/files/1/0494/9799/7471/files/komoxenelujujotudi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- wepugimi.weebly.com
- tavumake.weebly.com
- dutitujazekap.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report