SUSPICIOUS — normal_5f87017bee5c1.pdf
SUSPICIOUS — normal_5f87017bee5c1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e4230d76c44971e3d237be1b748eb78fe4d80dc90863ad216588c0be40852d5a - SHA-1:
33c8d5ccd58d65322715986933fac16c99a87348 - MD5:
7c1735f51022b98fa5acadf83ac57ab1 - ssdeep:
1536:fGFNk1lXAWJl77Fn1RSqz5SMm4rxv9+nctc04pWh3pjEAOvYoZWSSpk0Axl2dzO2:OF2lyBMmqB9+ctc046qvYothTUidw - TLSH:
T1193ACFF351DBEC8D7A8A9B83EEA61115704ACBC861639B31248C775DE97C66C3F41A00 - Submitted as: normal_5f87017bee5c1.pdf
- File type: pdf · Size: 94731 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=%25D8%25B1%25D9%2585%25D8%25A7%25D9%2586+%25D8%25B9%25D8%25A7%25D8%25B4%25D9%2582%25D8%25A7%25D9%2586%25D9%2587+%25D9%2587%25D9%2585%25D8%25AE%25D9%2588%25D9%2586%25D9%2587+pdf, https://cdn.shopify.com/s/files/1/0268/7628/1031/files/enigmatic_fortress_event_chain_guide.pdf, https://cdn.shopify.com/s/files/1/0435/1868/9434/files/raze_3_unblocked_at_school_66.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=%25D8%25B1%25D9%2585%25D8%25A7%25D9%2586+%25D8%25B9%25D8%25A7%25D8%25B4%25D9%2582%25D8%25A7%25D9%2586%25D9%2587+%25D9%2587%25D9%2585%25D8%25AE%25D9%2588%25D9%2586%25D9%2587+pdf
- https://cdn.shopify.com/s/files/1/0268/7628/1031/files/enigmatic_fortress_event_chain_guide.pdf
- https://cdn.shopify.com/s/files/1/0435/1868/9434/files/raze_3_unblocked_at_school_66.pdf
- https://cdn.shopify.com/s/files/1/0495/1402/1030/files/jagemajazupuguvuserepu.pdf
- https://cdn.shopify.com/s/files/1/0436/0385/3476/files/standard_and_scientific_notation_worksheet_answer_key.pdf
- https://uploads.strikinglycdn.com/files/1b5c7303-2e67-48bc-8cb8-b80e6182b8b6/4619178754.pdf
- https://uploads.strikinglycdn.com/files/ac20256e-9920-4a70-8098-a0fa8ae84fad/83520081436.pdf
- https://uploads.strikinglycdn.com/files/ed6d8374-c3e2-4adb-9d66-202f45034120/38291744560.pdf
- https://uploads.strikinglycdn.com/files/51dd2007-52e8-472d-858e-285a6a4ee6a9/53124605219.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f86f878c78d8.pdf
- https://cdn-cms.f-static.net/uploads/4365636/normal_5f86fce112241.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f86f8823a286.pdf
- https://cdn.shopify.com/s/files/1/0491/7094/0070/files/block_private_number_android.pdf
- https://cdn.shopify.com/s/files/1/0482/9318/3650/files/who_are_the_fathers_of_sociology.pdf
- https://cdn.shopify.com/s/files/1/0499/2860/1761/files/android_storing_data_locally.pdf
- https://cdn.shopify.com/s/files/1/0499/3328/7592/files/hot_spots_during_the_cold_war.pdf
- https://site-1039907.mozfiles.com/files/1039907/85604085281.pdf
- https://site-1040312.mozfiles.com/files/1040312/92290525939.pdf
- https://site-1048568.mozfiles.com/files/1048568/dofitaxunete.pdf
- https://site-1036625.mozfiles.com/files/1036625/metabo.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/kuwekewugi.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/zutilipevozafeguwu.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/7775416.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/3409757.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/linurigaruxox.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1039907.mozfiles.com
- site-1040312.mozfiles.com
- site-1048568.mozfiles.com
- site-1036625.mozfiles.com
- zafozudakajadev.weebly.com
- guwomenod.weebly.com
- jakedekokobara.weebly.com
- fijojonibiw.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report