SUSPICIOUS — normal_5f88baa3592db.pdf
SUSPICIOUS — normal_5f88baa3592db.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
bb5cbf33d28022c69d2372df3210551e3cea9342056a1296cfabdeec9e9c7062 - SHA-1:
94859c1d844bd92f96bd27ea105d2f1347fa0470 - MD5:
a2374078b7d19e74e62366b486c0a7bb - ssdeep:
768:bgGzpDQpt080mxXaVoaBpZEZKByDI4f8js6GOvRdSAWfOHGCHtN9ibd1LA:kGFUpt3kxyDIwd6vSAWfOHhHtSbd1LA - TLSH:
T1B0338DF75097ED4C7A8B9F13ADEB29695049E3885232A764408C7B2CD07C7BD7E00A61 - Submitted as: normal_5f88baa3592db.pdf
- File type: pdf · Size: 49120 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=engineering+mechanics+all+formulas+pdf, https://uploads.strikinglycdn.com/files/568d99ed-3ca2-48f2-9459-28730148c256/73019065167.pdf, https://uploads.strikinglycdn.com/files/e1b923ad-cb38-4d94-87ad-a3322ab1aabb/gifujabebomowevefuv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=engineering+mechanics+all+formulas+pdf
- https://uploads.strikinglycdn.com/files/568d99ed-3ca2-48f2-9459-28730148c256/73019065167.pdf
- https://uploads.strikinglycdn.com/files/e1b923ad-cb38-4d94-87ad-a3322ab1aabb/gifujabebomowevefuv.pdf
- https://uploads.strikinglycdn.com/files/e1fc7a88-cd64-480d-b4c2-7f54587d24ea/vixegaloza.pdf
- https://uploads.strikinglycdn.com/files/3c9ee0d4-359e-4e46-8342-2352fbde7f3d/15486372832.pdf
- https://uploads.strikinglycdn.com/files/a184d66e-2091-42ad-97f5-41f3c538b0f5/repixer.pdf
- https://texitanoz.weebly.com/uploads/1/3/0/7/130739996/mabapigar.pdf
- https://bewupoterefi.weebly.com/uploads/1/3/1/3/131380107/4014890.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/8a68c5dc19.pdf
- https://lajojixuvoporor.weebly.com/uploads/1/3/0/7/130738555/lavegulexuneme_jorexo_kijalujivoze_lokuvugafomiket.pdf
- https://zevigetadafuwun.weebly.com/uploads/1/3/0/9/130969942/c13a2c1.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f86f4b58bf8e.pdf
- https://cdn-cms.f-static.net/uploads/4366961/normal_5f87494e539d6.pdf
- https://cdn-cms.f-static.net/uploads/4369932/normal_5f88ba6a4ae27.pdf
- https://cdn-cms.f-static.net/uploads/4368227/normal_5f87aadf36a59.pdf
- https://cdn-cms.f-static.net/uploads/4365570/normal_5f87028c91605.pdf
- https://cdn.shopify.com/s/files/1/0434/1887/8104/files/galaxy_s7_android_9_2020.pdf
- https://cdn.shopify.com/s/files/1/0499/9377/7302/files/flying_15_weeks_pregnant.pdf
- https://uploads.strikinglycdn.com/files/5da2d289-6ffc-4799-96ba-d1d6c3f6f9f0/nebutugirewufotaluxila.pdf
- https://uploads.strikinglycdn.com/files/6bae3617-f7f8-49b1-835e-41c13c2a5ff9/zakipejulizag.pdf
- https://uploads.strikinglycdn.com/files/426ac664-1ae3-41cf-a0f0-f868aeab199d/82094747785.pdf
- https://uploads.strikinglycdn.com/files/00cbdf41-c2c3-4d21-8d62-74b16dab7a43/568864532.pdf
- https://site-1043195.mozfiles.com/files/1043195/subtraction_with_regrouping_three_digit_numbers_worksheets.pdf
- https://site-1042549.mozfiles.com/files/1042549/gajiwom.pdf
- https://site-1039330.mozfiles.com/files/1039330/clearing_and_forwarding_process.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- texitanoz.weebly.com
- bewupoterefi.weebly.com
- boguvetasitob.weebly.com
- lajojixuvoporor.weebly.com
- zevigetadafuwun.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1043195.mozfiles.com
- site-1042549.mozfiles.com
- site-1039330.mozfiles.com
- site-1044202.mozfiles.com
- site-1038572.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report