SUSPICIOUS — normal_5f89b92bd5a9c.pdf
SUSPICIOUS — normal_5f89b92bd5a9c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e3dba8510224b5759e4d58889e813280ef81926b12d9d7278b6fe0113ec8593d - SHA-1:
c0a9c313ce9b2bb3b3f743e838edf35c5d82ec3e - MD5:
a19eb1812e80735ca3e4fdcb7e4843f7 - ssdeep:
768:EGgGzpD2p6sEbrU66aRqgzGIwWCvPy/O209gRu7luB1/VuHJXnG5V/BkESBIzqoi:WGFyp+GbNQ1/mJXGj63iDOAWL6nD4 - TLSH:
T1C333AEF311A3EE8C7E8F5F1369EA1419654AC64D6133A7A00888772CD5BCAFD6F10960 - Submitted as: normal_5f89b92bd5a9c.pdf
- File type: pdf · Size: 49215 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=8th+class+english+guide+pdf+free+download, https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/4140341.pdf, https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/bibesekukemugedovofa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=8th+class+english+guide+pdf+free+download
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/4140341.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/bibesekukemugedovofa.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/4abdc26250fc54.pdf
- https://femitinekabel.weebly.com/uploads/1/3/1/4/131437683/2950530.pdf
- https://cdn.shopify.com/s/files/1/0481/2796/7395/files/desogodixo.pdf
- https://cdn.shopify.com/s/files/1/0496/2333/5063/files/road_warrior_hawk_haircut.pdf
- https://cdn.shopify.com/s/files/1/0504/1573/0886/files/taiwan_vpn_crack_apk.pdf
- https://cdn.shopify.com/s/files/1/0496/0727/8744/files/46695502260.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f870d94ea799.pdf
- https://cdn-cms.f-static.net/uploads/4366405/normal_5f87e3a5b93df.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f870b862412d.pdf
- https://cdn-cms.f-static.net/uploads/4365542/normal_5f870bf91531a.pdf
- https://cdn-cms.f-static.net/uploads/4368243/normal_5f87b67919b6b.pdf
- https://lajojixuvoporor.weebly.com/uploads/1/3/0/7/130738555/517984138e1fcbe.pdf
- https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/8501393.pdf
- https://xodetawutal.weebly.com/uploads/1/3/0/7/130774968/2661374.pdf
- https://cdn.shopify.com/s/files/1/0266/8131/1418/files/9841028890.pdf
- https://cdn.shopify.com/s/files/1/0484/0826/4862/files/run_activexobject_in_chrome.pdf
- https://cdn.shopify.com/s/files/1/0496/7553/4488/files/25333309977.pdf
- https://uploads.strikinglycdn.com/files/058e11ee-2141-4ccd-be8a-e8499cf2e255/bajoxutafuvanedagug.pdf
- https://uploads.strikinglycdn.com/files/206bfa99-87c1-44f7-9540-15ee3cd1c5d8/87012568700.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- boguvetasitob.weebly.com
- jemiwuwavaza.weebly.com
- dapujevubo.weebly.com
- femitinekabel.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- lajojixuvoporor.weebly.com
- fotejisatowonu.weebly.com
- xodetawutal.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report