SUSPICIOUS — normal_5f95a1b3df4da.pdf
SUSPICIOUS — normal_5f95a1b3df4da.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c0156959521a6654779e174651bab1eed6e71a1b842558d9eabd517c568db5c6 - SHA-1:
75a7ec1d55cd85f2ebc26b331f649629d04f6c65 - MD5:
030a6c2483e5a05b2949e88633bb4d99 - ssdeep:
1536:OGFvpC3Ufccjk+RN1qnWalBLlVQZFOeobkc58:3FvpUUrjkRn1lBpVbeoQX - TLSH:
T11535D0F34067DD0C7A9AAB03ADBA125CA149C7887336DAB16688775CD17C27C7E10A31 - Submitted as: normal_5f95a1b3df4da.pdf
- File type: pdf · Size: 61062 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=visible+thinking+routines+posters+pdf, https://cdn.shopify.com/s/files/1/0430/8575/8618/files/jumotavipolikazofejipibav.pdf, https://cdn.shopify.com/s/files/1/0495/5537/4247/files/letozadaremaj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=visible+thinking+routines+posters+pdf
- https://s3.amazonaws.com/tejuvonixag/easton_arrow_selection_chart.pdf
- https://s3.amazonaws.com/rubidokezive/neural_networks_and_deep_learning_a_textbook_aggarwal.pdf
- https://s3.amazonaws.com/zetare/13079020990.pdf
- https://cdn.shopify.com/s/files/1/0430/8575/8618/files/jumotavipolikazofejipibav.pdf
- https://cdn.shopify.com/s/files/1/0495/5537/4247/files/letozadaremaj.pdf
- https://cdn.shopify.com/s/files/1/0436/9560/3865/files/house_of_troy_picture_lighting.pdf
- https://uploads.strikinglycdn.com/files/4bd2adf5-be8b-4676-8e2f-a86531b58bec/redurijuvatesijukerot.pdf
- https://uploads.strikinglycdn.com/files/5357a44e-7dfd-4482-8f18-b6b809ef7787/multiplier_par_10_ce1.pdf
- https://cdn-cms.f-static.net/uploads/4370063/normal_5f8e36f7cc4ad.pdf
- https://cdn-cms.f-static.net/uploads/4384472/normal_5f8d06f7f3621.pdf
- https://cdn-cms.f-static.net/uploads/4366005/normal_5f9273ac66004.pdf
- https://s3.amazonaws.com/susopuzupure/xepekomorixemugaj.pdf
- https://s3.amazonaws.com/midaguvimabof/degree_of_adjectives_exercises_with_answers.pdf
- https://s3.amazonaws.com/kigavanus/technical_writing_and_communication_skills.pdf
- https://uploads.strikinglycdn.com/files/7a744a13-26b5-47ef-9edd-b312bc6e1628/jikusaladimi.pdf
- https://uploads.strikinglycdn.com/files/339b3a5a-7bee-42b8-9d47-33b8a6ecb2d5/gotiwofitupezotex.pdf
- https://uploads.strikinglycdn.com/files/2109ccaf-2607-43d2-9bc1-bccca6e7b332/fevosapadalovurobe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report