SUSPICIOUS — normal_5f875e5925f0b.pdf
SUSPICIOUS — normal_5f875e5925f0b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b765a9a91b9828a6f0f63db809c88eaf67e47f4dbef494be821299e238159417 - SHA-1:
211637d8fd2e4a1116523ddd49c1826ec24ccfe2 - MD5:
d9bef3dbe4a2985f8f2672908d4ea6d4 - ssdeep:
768:SgGzpDOp4UcLILfKv8XCnG7BTgE9JdcGVy/YbQAisG7B7NQmfTrFjdBNAJ3mJxnL:PGFSp4uCG7S0JNs/AaNQmfTrFjDaJutt - TLSH:
T1C9328EF351B7DC8C79869B03AEEA294DA14ED74851329B6055887A3CC9BC2BD3F00911 - Submitted as: normal_5f875e5925f0b.pdf
- File type: pdf · Size: 46831 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=montaigne+essays+penguin+pdf, https://cdn-cms.f-static.net/uploads/4366982/normal_5f872a171a34b.pdf, https://cdn-cms.f-static.net/uploads/4365584/normal_5f874a288ff0c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=montaigne+essays+penguin+pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f872a171a34b.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f874a288ff0c.pdf
- https://cdn-cms.f-static.net/uploads/4367633/normal_5f875674673e0.pdf
- https://sakuvida.weebly.com/uploads/1/3/0/7/130775714/bazesatoba-kanoj-ronagagekixik.pdf
- https://sibakixode.weebly.com/uploads/1/3/2/8/132814768/vajomepidibaxi.pdf
- https://jukafubu.weebly.com/uploads/1/3/0/8/130874261/ebaf340.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/govorikepudago-gixidawele-wawep-xoxebilepadevu.pdf
- https://site-1043095.mozfiles.com/files/1043095/dujunokepipejezif.pdf
- https://site-1041284.mozfiles.com/files/1041284/1825095657.pdf
- https://site-1038703.mozfiles.com/files/1038703/13195364469.pdf
- https://site-1043805.mozfiles.com/files/1043805/8920129325.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/36ce75ac.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/fesixukorupu.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/jixidused.pdf
- https://vikumeniwexawud.weebly.com/uploads/1/3/0/9/130969440/d585eab8343c0.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/4054812.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/3794757.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/6431815.pdf
- https://cdn-cms.f-static.net/uploads/4366313/normal_5f87143fa193f.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f8735690f130.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f87524572ae4.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- sakuvida.weebly.com
- sibakixode.weebly.com
- jukafubu.weebly.com
- dutitujazekap.weebly.com
- site-1043095.mozfiles.com
- site-1041284.mozfiles.com
- site-1038703.mozfiles.com
- site-1043805.mozfiles.com
- jakedekokobara.weebly.com
- jatorogerujew.weebly.com
- vikumeniwexawud.weebly.com
- rezizeme.weebly.com
- bedizegoresupa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report