SUSPICIOUS — normal_5f8f57342d0bf.pdf
SUSPICIOUS — normal_5f8f57342d0bf.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
ed514b169aac35c65e23286ad07ec761dbce75fabe545ef0e23babfe4df74eb1 - SHA-1:
665493c10affd6f4e071a1855d3362c5dc12e406 - MD5:
d03ab3a4614feb0d3de1b7251061f0e0 - ssdeep:
1536:NGFhpsZdSYVHVSMAR9PRmqm0y7cFwjEC1WNNqeG7vH6VN5rhwYQ92obzJSQ:QFhpOSeHVSMADMqS7cWZwtG7i7wfhbz3 - TLSH:
T1DE39CEB31063DCEC6F879F87A9F5639D612ADE886162E26044C8A61CC47C6FD6F08D11 - Submitted as: normal_5f8f57342d0bf.pdf
- File type: pdf · Size: 89122 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=jlg+660sj+operator%2527s+manual+pdf, https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/2697538.pdf, https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/mofep.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=jlg+660sj+operator%2527s+manual+pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/2697538.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/mofep.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/5734794.pdf
- https://cdn.shopify.com/s/files/1/0433/7857/3468/files/68658196517.pdf
- https://cdn.shopify.com/s/files/1/0432/7827/0628/files/94861391078.pdf
- https://cdn.shopify.com/s/files/1/0436/2846/2233/files/91649354315.pdf
- https://uploads.strikinglycdn.com/files/0c0a6a00-8751-4e60-a68e-e05f6162271d/igor_marcel_caffarena_jorge_salinas.pdf
- https://uploads.strikinglycdn.com/files/a03df806-c942-45a9-a8f7-7375e8b5cab0/sesexedimuvirakupeno.pdf
- https://uploads.strikinglycdn.com/files/9b9dcaa4-3a12-4ef1-a4db-1eb9a688a8b8/sirij.pdf
- https://fisizupesaxog.weebly.com/uploads/1/3/1/6/131636899/nanajuzejurevibi.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/fakinutodunod.pdf
- https://cdn.shopify.com/s/files/1/0502/7355/0533/files/ejercicios_ecuaciones_trigonometricas_1_bachillerato.pdf
- https://cdn.shopify.com/s/files/1/0498/8076/0475/files/josonakivesakuzaliwewuvus.pdf
- https://cdn.shopify.com/s/files/1/0476/9434/8454/files/72755380622.pdf
- https://uploads.strikinglycdn.com/files/ba9dedf5-ec34-4192-bdf6-8d519664e9e5/venapu.pdf
- https://uploads.strikinglycdn.com/files/5ed065de-150a-41c5-b85d-64aa2c469ef3/gugeroledevakememijifubaf.pdf
- https://uploads.strikinglycdn.com/files/ff6f655d-203b-4c51-8ee8-ffe622ee1dc6/sofolezawi.pdf
- https://uploads.strikinglycdn.com/files/58da664b-e32f-4921-b5a0-061969110e59/company_of_heroes_tales_of_valor_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- dimaxafazeza.weebly.com
- guwomenod.weebly.com
- rabifupokuwu.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- fisizupesaxog.weebly.com
- riwisasivituw.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report