SUSPICIOUS — normal_5f893aa1aec9c.pdf
SUSPICIOUS — normal_5f893aa1aec9c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b7f2a056c3649b3a84fe453979ad6edfe916715a27738509805520b5b9543a11 - SHA-1:
2d2c36e3bc704ff314687a17afad8d1ac5d29170 - MD5:
acc3004c7bd2411b66f2eae44d65835f - ssdeep:
768:sRgGzpDWp991RzbgA9djuPKvpgM3a8w8ysPyfhKZ39/5IFr5VwGqeM+gU2bb:nGFip9GA9OKGM3Gq/5IB5VwGqugUIb - TLSH:
T132329FF350A3FD8CBE86AB036EA71499A549C6CC203296A0448C3B6DC5BC5BD6F51711 - Submitted as: normal_5f893aa1aec9c.pdf
- File type: pdf · Size: 43468 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=turn+off+chrome+updates+android, https://cdn.shopify.com/s/files/1/0440/9245/7112/files/96569636750.pdf, https://cdn.shopify.com/s/files/1/0484/4122/9470/files/bosch_e24_watertap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=turn+off+chrome+updates+android
- https://cdn.shopify.com/s/files/1/0440/9245/7112/files/96569636750.pdf
- https://cdn.shopify.com/s/files/1/0484/4122/9470/files/bosch_e24_watertap.pdf
- https://cdn.shopify.com/s/files/1/0492/3185/5772/files/palipepirolavinomot.pdf
- https://uploads.strikinglycdn.com/files/7451a3f6-7758-4d69-ab26-c8fda375d349/xerejonapidubasa.pdf
- https://cdn.shopify.com/s/files/1/0483/3601/1417/files/rofagitidezobuk.pdf
- https://cdn.shopify.com/s/files/1/0435/0096/1947/files/87550846385.pdf
- https://uploads.strikinglycdn.com/files/33585555-6c50-4385-b4fb-e42db614f18a/16566671735.pdf
- https://uploads.strikinglycdn.com/files/5639397d-4dd3-4eda-a392-a5694c84fe0d/884539877.pdf
- https://uploads.strikinglycdn.com/files/66aeb316-f5af-48c9-9db7-2b8758d2bdb3/88033007167.pdf
- https://cdn-cms.f-static.net/uploads/4365613/normal_5f8746a77bf99.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f8744740f08c.pdf
- https://uploads.strikinglycdn.com/files/9d0cfdf0-bc09-483c-9ad4-b8aaaafcac2c/rabenumadepomoripi.pdf
- https://uploads.strikinglycdn.com/files/d8ee9934-4347-477a-bf04-3fbb281d40f7/rekugesuxavi.pdf
- https://uploads.strikinglycdn.com/files/b732b550-b14c-48af-bf98-456eb452a538/lamusodonigozid.pdf
- https://uploads.strikinglycdn.com/files/22c18343-5db8-4042-9016-922529dfa930/vuvibojod.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report