SUSPICIOUS — normal_5f89060366c55.pdf
SUSPICIOUS — normal_5f89060366c55.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
be36e6262eaa14af83e8530aa41bb83d286936cd3bfe7a1add0ea0c64d2df570 - SHA-1:
b51b46cfd4bbd7b39d79f7b30650bfddaccfcfbb - MD5:
37b96352974de5a5a66b4e2ff5ff037b - ssdeep:
768:ngGzpDnp2kHCt8nR/DbFK0U5yKgNZlFsU9A4eG2cgIZ3BrsOwXC0yTTZINLqzuQX:gGF7plfFsUaJG2cgIRlsOwXC0QTZINup - TLSH:
T1D0329DF30097ED4CBA8E6F03A9EB11599185C3896173E66050C8772CD1BCAFD6F00A51 - Submitted as: normal_5f89060366c55.pdf
- File type: pdf · Size: 44754 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=ged+math+review+pdf, https://cdn.shopify.com/s/files/1/0484/1052/5853/files/vagubetedufepuvemuvo.pdf, https://cdn.shopify.com/s/files/1/0434/8385/7053/files/nenizefo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=ged+math+review+pdf
- https://cdn.shopify.com/s/files/1/0484/1052/5853/files/vagubetedufepuvemuvo.pdf
- https://cdn.shopify.com/s/files/1/0434/8385/7053/files/nenizefo.pdf
- https://cdn.shopify.com/s/files/1/0481/7987/1911/files/22040459229.pdf
- https://cdn.shopify.com/s/files/1/0484/1881/6157/files/best_buy_waterford_lakes_orlando_florida.pdf
- https://cdn.shopify.com/s/files/1/0268/9024/0179/files/66894164735.pdf
- https://cdn.shopify.com/s/files/1/0495/4911/5544/files/68758785508.pdf
- https://cdn.shopify.com/s/files/1/0268/7949/2270/files/inner_engineering_a_yogis_guide_to_joy_quotes.pdf
- https://cdn.shopify.com/s/files/1/0484/9857/3474/files/concepto_de_normas_sociales.pdf
- https://site-1043885.mozfiles.com/files/1043885/pimek.pdf
- https://site-1042020.mozfiles.com/files/1042020/wobazugubidoxag.pdf
- https://site-1040299.mozfiles.com/files/1040299/kejakevekapaj.pdf
- https://site-1040171.mozfiles.com/files/1040171/fukabuwonuzaxib.pdf
- https://site-1044202.mozfiles.com/files/1044202/mechanical_engineering_machine_design_handbook.pdf
- https://site-1039815.mozfiles.com/files/1039815/27756516698.pdf
- https://site-1041591.mozfiles.com/files/1041591/97005458391.pdf
- https://cdn-cms.f-static.net/uploads/4368475/normal_5f88cb88d1ac0.pdf
- https://cdn-cms.f-static.net/uploads/4368772/normal_5f88cda4486ba.pdf
- https://cdn.shopify.com/s/files/1/0467/7468/1753/files/jowifixegas.pdf
- https://cdn.shopify.com/s/files/1/0498/7859/7790/files/weralo.pdf
- https://cdn.shopify.com/s/files/1/0433/0700/8168/files/bifomuwojijonam.pdf
- https://cdn.shopify.com/s/files/1/0496/6360/6933/files/jedefidereruzokuxavupulis.pdf
- https://cdn.shopify.com/s/files/1/0483/4797/1735/files/81781327947.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1043885.mozfiles.com
- site-1042020.mozfiles.com
- site-1040299.mozfiles.com
- site-1040171.mozfiles.com
- site-1044202.mozfiles.com
- site-1039815.mozfiles.com
- site-1041591.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report