SUSPICIOUS — normal_5f872d2a11ced.pdf
SUSPICIOUS — normal_5f872d2a11ced.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ba072fe44a562783881bdd08e8e6a0636f87057e81761015033b332a30638f9a - SHA-1:
dd9a37734a8ddb7f2c4e3a73189dabaa484356be - MD5:
9e865b6acae0e36ab611b7cfee9d52e0 - ssdeep:
768:oHgGzpDApwN6GAeyPx1c+klQC+l3U9S+0rHPIzwDHvbf+1fbV7rbvMP:1GFspka9dRl3U9S+bzwjbm1fx7vMP - TLSH:
T12F32BFF310A7ED8C799A9753AEA6254D2045D38D6133A7A1488C767CD0BC7BDBE10C21 - Submitted as: normal_5f872d2a11ced.pdf
- File type: pdf · Size: 46995 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=how+to+factory+reset+android+zte+tracfone, https://cdn.shopify.com/s/files/1/0498/5277/6603/files/heal_thyself_for_health_and_longevity_queen_afua.pdf, https://cdn.shopify.com/s/files/1/0476/6747/8694/files/79719941899.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=how+to+factory+reset+android+zte+tracfone
- https://cdn.shopify.com/s/files/1/0498/5277/6603/files/heal_thyself_for_health_and_longevity_queen_afua.pdf
- https://cdn.shopify.com/s/files/1/0476/6747/8694/files/79719941899.pdf
- https://cdn.shopify.com/s/files/1/0437/2312/8986/files/need_for_speed_hot_pursuit_2_cheats_pc_unlock_everything.pdf
- https://cdn.shopify.com/s/files/1/0436/9560/3862/files/pamuropumos.pdf
- https://site-1044118.mozfiles.com/files/1044118/kolezixixikeriwepetet.pdf
- https://site-1040665.mozfiles.com/files/1040665/lejitekajoropifaxefonowu.pdf
- https://site-1038952.mozfiles.com/files/1038952/22346772444.pdf
- https://site-1043699.mozfiles.com/files/1043699/xufoxebirer.pdf
- https://site-1036965.mozfiles.com/files/1036965/70940016954.pdf
- https://site-1038597.mozfiles.com/files/1038597/zabexag.pdf
- https://site-1042585.mozfiles.com/files/1042585/24354917583.pdf
- https://site-1039279.mozfiles.com/files/1039279/49490244624.pdf
- https://site-1041851.mozfiles.com/files/1041851/90489372702.pdf
- https://site-1043365.mozfiles.com/files/1043365/4708515098.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/lozasuwexekizis-wewozugegi-doriruruze-fagowawe.pdf
- https://giwakatunu.weebly.com/uploads/1/3/1/4/131437107/xaloni.pdf
- https://site-1036821.mozfiles.com/files/1036821/jidise.pdf
- https://site-1043908.mozfiles.com/files/1043908/xenigumibeb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1044118.mozfiles.com
- site-1040665.mozfiles.com
- site-1038952.mozfiles.com
- site-1043699.mozfiles.com
- site-1036965.mozfiles.com
- site-1038597.mozfiles.com
- site-1042585.mozfiles.com
- site-1039279.mozfiles.com
- site-1041851.mozfiles.com
- site-1043365.mozfiles.com
- loguxofe.weebly.com
- giwakatunu.weebly.com
- site-1036821.mozfiles.com
- site-1043908.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report