SUSPICIOUS — normal_5f87632c10bce.pdf
SUSPICIOUS — normal_5f87632c10bce.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
c8aef28908ae907f3760c7827faefdc66532f006128eb60020fd0cb22a4e0490 - SHA-1:
6851da7fedf8e3408e98d97fe7fcddb73a59650e - MD5:
82978f49a06e7710816d3ffec362c882 - ssdeep:
768:zgGzpDbpNQsC44Qm5cm+IV8LNYLnI1jHf5KDnLmBiJS:MGFPpo5vV8LsI1j/QDnyKS - TLSH:
T1DE306BF30093EC8CBA8F6F079EEB2199508AD78D6176D7A00488676DD47C9AD7F40960 - Submitted as: normal_5f87632c10bce.pdf
- File type: pdf · Size: 38963 bytes
- Verdict: suspicious (35/100)
Detections (2 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=chef%2527s+choice+1520+manual, https://cdn-cms.f-static.net/uploads/4365652/normal_5f8715f1adc84.pdf, https://cdn-cms.f-static.net/uploads/4366055/normal_5f875acf6efb1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=chef%2527s+choice+1520+manual
- https://cdn-cms.f-static.net/uploads/4365652/normal_5f8715f1adc84.pdf
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f875acf6efb1.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f8755fd6de89.pdf
- https://site-1040601.mozfiles.com/files/1040601/vector_analysis_schaum_series_solution_manual.pdf
- https://site-1042919.mozfiles.com/files/1042919/zilenopatajeva.pdf
- https://site-1039438.mozfiles.com/files/1039438/winetun.pdf
- https://site-1042270.mozfiles.com/files/1042270/97724887602.pdf
- https://site-1043222.mozfiles.com/files/1043222/40386637182.pdf
- https://uploads.strikinglycdn.com/files/b72c9207-50d6-45f8-a1e5-ba87bd0c49ed/2705758799.pdf
- https://uploads.strikinglycdn.com/files/33ade842-cf40-45c2-b85c-3e0c2e3ef33e/gokusutemiwoxeguba.pdf
- https://uploads.strikinglycdn.com/files/1658ef9f-201e-4474-9c8e-3317f5c18206/lozoladuripevexipisuzaze.pdf
- https://uploads.strikinglycdn.com/files/825d8b15-4fa8-4f26-8b20-b193181ce20b/mibufapirejitafasokap.pdf
- https://uploads.strikinglycdn.com/files/bd93bc2e-c1b2-41a1-b1b9-b1cdcefc7e3a/xovigirunipadulis.pdf
- https://site-1038494.mozfiles.com/files/1038494/32138165400.pdf
- https://site-1040260.mozfiles.com/files/1040260/90687810613.pdf
- https://site-1043130.mozfiles.com/files/1043130/42208960666.pdf
- https://site-1039711.mozfiles.com/files/1039711/91608807230.pdf
- https://site-1038627.mozfiles.com/files/1038627/24866319170.pdf
- https://uploads.strikinglycdn.com/files/236b37ec-0ffe-429b-901b-b8ecf8a98ed2/jaxixe.pdf
- https://uploads.strikinglycdn.com/files/aa1decf8-cbea-411a-9580-b1ffb528a556/34271045750.pdf
- https://uploads.strikinglycdn.com/files/b9f44962-3559-46c9-878c-c02906211dec/77956654187.pdf
- https://uploads.strikinglycdn.com/files/9bba3926-7758-49b1-a724-97c1dfadfb1c/963032852.pdf
- https://site-1048273.mozfiles.com/files/1048273/wesumituv.pdf
- https://site-1041210.mozfiles.com/files/1041210/zuvagamuvavebepemuraxalef.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1040601.mozfiles.com
- site-1042919.mozfiles.com
- site-1039438.mozfiles.com
- site-1042270.mozfiles.com
- site-1043222.mozfiles.com
- uploads.strikinglycdn.com
- site-1038494.mozfiles.com
- site-1040260.mozfiles.com
- site-1043130.mozfiles.com
- site-1039711.mozfiles.com
- site-1038627.mozfiles.com
- site-1048273.mozfiles.com
- site-1041210.mozfiles.com
- site-1039768.mozfiles.com
- site-1040975.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report