SUSPICIOUS — normal_5f87da88a3465.pdf
SUSPICIOUS — normal_5f87da88a3465.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
e6ce25471c73c2251b844e7ae5e1654537c7f81bfb1579f9cbd4f447c8f4ddd7 - SHA-1:
b7cdc33ad6cac9db236d2b7a7484d597c81f4d77 - MD5:
2a95305891dabd26465c512a2951d553 - ssdeep:
768:4ZgGzpDopsp05vw4DsaWJ0SxuqQIloD1QiQaHpozpKJ2psIKQyxHo937CZK/:bGFcp80ajmqiQaJC5p3yI937d/ - TLSH:
T17B33BEF31097ED4C6E86AB03BDEF19A52149D3896132E750588C7B2CD4BC6BC6F20560 - Submitted as: normal_5f87da88a3465.pdf
- File type: pdf · Size: 47863 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=k9+web+protection+for+android+phone, https://site-1036667.mozfiles.com/files/1036667/vubugedosumenaz.pdf, https://site-1039801.mozfiles.com/files/1039801/danugo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=k9+web+protection+for+android+phone
- https://site-1036667.mozfiles.com/files/1036667/vubugedosumenaz.pdf
- https://site-1039801.mozfiles.com/files/1039801/danugo.pdf
- https://site-1040171.mozfiles.com/files/1040171/53548490991.pdf
- https://site-1040559.mozfiles.com/files/1040559/33979857088.pdf
- https://site-1039314.mozfiles.com/files/1039314/53919790274.pdf
- https://site-1041944.mozfiles.com/files/1041944/puhu_tv_tablet_apk.pdf
- https://site-1042886.mozfiles.com/files/1042886/51952596015.pdf
- https://uploads.strikinglycdn.com/files/29ca4d91-ef83-4b86-b6fe-a6ca84c97191/67846974182.pdf
- https://uploads.strikinglycdn.com/files/1ee23c20-af80-460d-bc48-2910aa7b9c6f/78925015994.pdf
- https://uploads.strikinglycdn.com/files/fe3348df-ca9c-4ea7-a651-68130eae1cb4/zikofi.pdf
- https://uploads.strikinglycdn.com/files/ae9b1c24-57c5-41e2-a149-109a167cb807/73402787251.pdf
- https://cdn.shopify.com/s/files/1/0433/3197/7369/files/graphing_from_a_table_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0439/3415/4907/files/the_lake_house_kate_morton.pdf
- https://cdn.shopify.com/s/files/1/0266/8229/4469/files/gotaxotigunigebujir.pdf
- https://cdn.shopify.com/s/files/1/0499/8109/6096/files/real_world_parabolas.pdf
- https://cdn.shopify.com/s/files/1/0434/9011/5748/files/clash_of_clans_hileli_apk_son_srm.pdf
- https://cdn.shopify.com/s/files/1/0485/1879/1323/files/bikini_bottom_genetics_review_worksheet_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0438/6547/3189/files/bleach_squad_11_5th_seat.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/kemadifenozegi_dupovema_pukoxapexe.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/xusimob.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/kopiwu_gotatumeturi_bovejixegas_vivikow.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- site-1036667.mozfiles.com
- site-1039801.mozfiles.com
- site-1040171.mozfiles.com
- site-1040559.mozfiles.com
- site-1039314.mozfiles.com
- site-1041944.mozfiles.com
- site-1042886.mozfiles.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- rabifupokuwu.weebly.com
- jamuseramomuf.weebly.com
- keniwuki.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report