SUSPICIOUS — normal_5f89234834daa.pdf
SUSPICIOUS — normal_5f89234834daa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e5793573b3878b51a124bf3acec8dce2c9ad9ded471b5750f0664e58e220455f - SHA-1:
a04af48d724ea3a8490423fce907c796c5c63e07 - MD5:
ce88ec312dee0f9d78de17fca20d2bcd - ssdeep:
768:tvgGzpDMpa1ub8J8oAGQJ4RNrm5JTKn9y2RdZoLQuRZ/Y1QwdOL5DJhbepdic+eQ:WGFwp64N2RjcQu7ArO9bbyic+eG+Bebb - TLSH:
T1CE329EF710A3EC4C798B5B436DAB1168648BC38CA127A79045CC662DD4BC9FC7F40661 - Submitted as: normal_5f89234834daa.pdf
- File type: pdf · Size: 46919 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=best+mid+range+android+phone+2020+malaysia, https://cdn-cms.f-static.net/uploads/4368475/normal_5f888840f4120.pdf, https://cdn-cms.f-static.net/uploads/4372100/normal_5f890a41a6fc4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=best+mid+range+android+phone+2020+malaysia
- https://cdn-cms.f-static.net/uploads/4368475/normal_5f888840f4120.pdf
- https://cdn-cms.f-static.net/uploads/4372100/normal_5f890a41a6fc4.pdf
- https://cdn-cms.f-static.net/uploads/4366311/normal_5f875fb08ba1c.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f8731d597a96.pdf
- https://cdn-cms.f-static.net/uploads/4366397/normal_5f873a7c7f09f.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f8715101d8ea.pdf
- https://cdn-cms.f-static.net/uploads/4368248/normal_5f887b558e550.pdf
- https://cdn-cms.f-static.net/uploads/4371272/normal_5f8882be2791e.pdf
- https://cdn.shopify.com/s/files/1/0434/6668/6617/files/42884523262.pdf
- https://cdn.shopify.com/s/files/1/0497/5368/6180/files/plant_cell_image.pdf
- https://cdn.shopify.com/s/files/1/0495/9548/2261/files/escambia_county_clerk_of_courts_office.pdf
- https://cdn.shopify.com/s/files/1/0433/2906/1032/files/30089855910.pdf
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f872b7088b04.pdf
- https://cdn-cms.f-static.net/uploads/4369318/normal_5f891df1e6ded.pdf
- https://cdn-cms.f-static.net/uploads/4369336/normal_5f8906962fc50.pdf
- https://cdn-cms.f-static.net/uploads/4368265/normal_5f88f7c7af625.pdf
- https://uploads.strikinglycdn.com/files/55029a1b-5b4c-4e2e-933a-c9570fc5d362/mirujufejuremiretuzugol.pdf
- https://uploads.strikinglycdn.com/files/1fa73a5e-f570-4b50-8e13-39b697d14180/pelowasuduvonesato.pdf
- https://uploads.strikinglycdn.com/files/b0decb42-8f43-4e28-81c9-79906d5b8a9a/82459080924.pdf
- https://uploads.strikinglycdn.com/files/d475564a-62ad-4e6c-8781-8d3d09a3c646/bopegenoju.pdf
- https://site-1043967.mozfiles.com/files/1043967/on_writing_well_espaol.pdf
- https://site-1043289.mozfiles.com/files/1043289/85938905557.pdf
- https://site-1036811.mozfiles.com/files/1036811/kotoroki.pdf
- https://site-1038365.mozfiles.com/files/1038365/45182593686.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1043967.mozfiles.com
- site-1043289.mozfiles.com
- site-1036811.mozfiles.com
- site-1038365.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report