SUSPICIOUS — normal_5f870983d360d.pdf
SUSPICIOUS — normal_5f870983d360d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
bf56e1ebc0dc842ba600ecc2447c9e8794ec9a9e8085d79b339b20a7aacf501d - SHA-1:
079368865b1b8d2f9c846559d1b168e5c991a5f7 - MD5:
1e10001a889e8a645e566d998ac7329c - ssdeep:
1536:oGFKpA/W1JxdIhEPVTvpQGoDZVHYvkiZAwWN7z:FFKpA+JbIS9TvpQvXYs7F - TLSH:
T17036CFF310A7ED8D7A8B9F17ACAB142D608DD74DA126D790068CA71CD47C6FE6E40A40 - Submitted as: normal_5f870983d360d.pdf
- File type: pdf · Size: 67377 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=boolean+expression+in+compiler+design+pdf, https://cdn.shopify.com/s/files/1/0484/7815/9002/files/wamutila.pdf, https://cdn.shopify.com/s/files/1/0500/4047/1702/files/tatesubosepe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=boolean+expression+in+compiler+design+pdf
- https://cdn.shopify.com/s/files/1/0484/7815/9002/files/wamutila.pdf
- https://cdn.shopify.com/s/files/1/0500/4047/1702/files/tatesubosepe.pdf
- https://cdn.shopify.com/s/files/1/0502/9173/6741/files/wixatelugesewugikezam.pdf
- https://cdn.shopify.com/s/files/1/0501/0794/1029/files/rasewa.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/batagebexi.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f86fea543283.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f86fe7512fd6.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f53751ac3.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f86f55811991.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f86fafc4399b.pdf
- https://cdn.shopify.com/s/files/1/0482/3836/2786/files/12258447412.pdf
- https://cdn.shopify.com/s/files/1/0486/0300/5086/files/chamberlain_universal_garage_door_remote_instructions.pdf
- https://cdn.shopify.com/s/files/1/0434/0439/4646/files/rizelipowe.pdf
- https://cdn.shopify.com/s/files/1/0428/4776/4647/files/aas_33a_sjsu.pdf
- https://cdn.shopify.com/s/files/1/0497/1036/6899/files/vuvaw.pdf
- https://cdn.shopify.com/s/files/1/0496/6223/0685/files/police_report_request_letter_sample_sri_lanka.pdf
- https://cdn.shopify.com/s/files/1/0501/7046/2373/files/85932307280.pdf
- https://cdn.shopify.com/s/files/1/0431/8219/4852/files/94657627749.pdf
- https://uploads.strikinglycdn.com/files/145ec122-9daf-4b39-be85-62934d6bda7d/gijilof.pdf
- https://uploads.strikinglycdn.com/files/35d03e20-832a-4fdd-a288-db5175aa2296/wobikukezubufekizarezud.pdf
- https://uploads.strikinglycdn.com/files/679ad0ba-19ef-4f32-bdf2-538ca788b000/papatikokuvud.pdf
- https://uploads.strikinglycdn.com/files/a0a047aa-5ad9-4852-aa35-f1387951e1ab/42588069073.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- mojivimimujovo.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report