SUSPICIOUS — normal_5f8730fb1f588.pdf
SUSPICIOUS — normal_5f8730fb1f588.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
baa10044a2b39d429567c690ed652ea2b6167748b26cd59e34e3e84a628b3cb9 - SHA-1:
5be1e7912221986a6e7ace1faf9b2df45b18da36 - MD5:
99e84750454fd4842706aab774a9aa9e - ssdeep:
768:fgGzpDSpyHYUh1MEusxxjn9ki7nT7pWb0uUSgzFnqE7z6k6NL85ErROY:oGF+pCxjn5kb0ujgFqM6k6NL85ErROY - TLSH:
T1C6328DF35097EC9C7A4A6F03AE670199918AC38D2137A360448C376DD4BCAFD7E10A61 - Submitted as: normal_5f8730fb1f588.pdf
- File type: pdf · Size: 43770 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=http+injector+mod+pro+apk+free, https://uploads.strikinglycdn.com/files/c63696a7-9dcf-4105-ad95-4a2eece7b2b8/mufolikubikem.pdf, https://uploads.strikinglycdn.com/files/8b1714dc-69fc-431e-a672-f95c95e3dd6d/5635446789.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=http+injector+mod+pro+apk+free
- https://uploads.strikinglycdn.com/files/c63696a7-9dcf-4105-ad95-4a2eece7b2b8/mufolikubikem.pdf
- https://uploads.strikinglycdn.com/files/8b1714dc-69fc-431e-a672-f95c95e3dd6d/5635446789.pdf
- https://uploads.strikinglycdn.com/files/831ee69c-653a-4734-a051-dc92c6e79287/sefipirabobavezim.pdf
- https://site-1038774.mozfiles.com/files/1038774/65557373267.pdf
- https://uploads.strikinglycdn.com/files/a2f8c008-8072-439d-a158-e398b51cf25c/94639255391.pdf
- https://uploads.strikinglycdn.com/files/a54ab5f4-389d-41f0-9512-05a7e4c0df99/mesezasozamumuxevid.pdf
- https://uploads.strikinglycdn.com/files/cff23a60-55f7-40e7-89a0-83fd7092f8fd/50285353884.pdf
- https://uploads.strikinglycdn.com/files/d8f359f1-1876-4f60-88de-9851bb6a55ba/xuwebiravavesenitesogupu.pdf
- https://uploads.strikinglycdn.com/files/325b1768-2193-467c-8351-96234775835d/meweneforemewepivipuvubu.pdf
- https://uploads.strikinglycdn.com/files/3c0dfd8f-3bd6-4ddf-888f-86dbb68d540d/demufotadasupuna.pdf
- https://uploads.strikinglycdn.com/files/6703757d-97ee-43bf-8a40-6e06436a823e/47363773161.pdf
- https://cdn.shopify.com/s/files/1/0437/2434/1400/files/vonapubami.pdf
- https://cdn.shopify.com/s/files/1/0499/0359/9774/files/lil_boosie_net_worth_2020_forbes.pdf
- https://cdn.shopify.com/s/files/1/0462/9918/5312/files/percentage_composition_by_mass_worksheet.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f86fad7bd477.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f86feb832c2d.pdf
- https://cdn-cms.f-static.net/uploads/4366336/normal_5f871e2abd548.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f871d68a6b67.pdf
- Http://www.APK
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1038774.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
- www.apk
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report