SUSPICIOUS — normal_5f888ad026a01.pdf
SUSPICIOUS — normal_5f888ad026a01.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c26d49f2f15b5953241646117cb72ba291cdef66c834fae85b88d403ca8597f8 - SHA-1:
7ec6ac79952b7fa2bba13d828c8ad402f8ae4a74 - MD5:
d2785f94e31bd4d881c29c8013e562b8 - ssdeep:
768:1gGzpD5pDUa1o0cSQeEhosG3EXx4ZP9WnFEweJqLldWNyMJohyIyPni41dMtshPt:mGF1pDe4ZAReJCoy4TniCMtcPt - TLSH:
T162329EF3109BED4C7A86A7077DAA25451588C28DA233E764488CBB7CD5BC6BD7F00921 - Submitted as: normal_5f888ad026a01.pdf
- File type: pdf · Size: 44380 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=3+domains+of+life+worksheet, https://cdn.shopify.com/s/files/1/0496/8172/7640/files/town_of_greenburgh_water_bill.pdf, https://cdn.shopify.com/s/files/1/0428/5821/7631/files/46253507354.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=3+domains+of+life+worksheet
- https://cdn.shopify.com/s/files/1/0496/8172/7640/files/town_of_greenburgh_water_bill.pdf
- https://cdn.shopify.com/s/files/1/0428/5821/7631/files/46253507354.pdf
- https://cdn.shopify.com/s/files/1/0496/1517/5829/files/flip_flop_frequency_divider.pdf
- https://cdn-cms.f-static.net/uploads/4369774/normal_5f8856a918b01.pdf
- https://cdn.shopify.com/s/files/1/0499/8129/2706/files/age_of_civilization_2_android_gameplay.pdf
- https://cdn.shopify.com/s/files/1/0496/1530/6915/files/lafagogosuliwozobup.pdf
- https://cdn.shopify.com/s/files/1/0459/8861/0215/files/polynomial_functions_3.2_answer_key.pdf
- https://site-1039449.mozfiles.com/files/1039449/bopebido.pdf
- https://site-1044240.mozfiles.com/files/1044240/jogagefufadanidasixewudu.pdf
- https://site-1044417.mozfiles.com/files/1044417/noxobotowogakuwolosap.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f87252592983.pdf
- https://cdn-cms.f-static.net/uploads/4367617/normal_5f8753011cba1.pdf
- https://cdn-cms.f-static.net/uploads/4368249/normal_5f886b4919d26.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f87028db3ed8.pdf
- https://cdn.shopify.com/s/files/1/0480/0708/6239/files/66212283717.pdf
- https://cdn.shopify.com/s/files/1/0434/0118/3397/files/fog_of_love_rules.pdf
- https://cdn.shopify.com/s/files/1/0430/8716/7645/files/79328297433.pdf
- https://cdn.shopify.com/s/files/1/0496/3100/2777/files/business_strategy_game_guide_2019.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1039449.mozfiles.com
- site-1044240.mozfiles.com
- site-1044417.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report