SUSPICIOUS — normal_5f873dd156353.pdf
SUSPICIOUS — normal_5f873dd156353.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
efaaa4dfc82cabfd70c972b2b5afd630e522c45aaeb4047ee526296bfe65c326 - SHA-1:
42d875f5012a5baf6c15c1cf38234730a5b23e73 - MD5:
81c7facb3e74ce412aa22437db00091e - ssdeep:
768:uDgGzpDYp5wjgQMG+YdcCdYWOSXcmsdg6IO1il9gDTbTexIt3ZHfceb9ibNIOjg3:vGFMp5XSM+5ED7Ht9ibNIlaHyl - TLSH:
T14D329EF350A7EC8E3A4BAF436DE71059548AD74DA133A6A10088772CD47CABE7F50911 - Submitted as: normal_5f873dd156353.pdf
- File type: pdf · Size: 46163 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=gta+5+free+download+for+android+ios, https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/bosilo_ginasesif.pdf, https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/tolefogi_fiderute_lotozipo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=gta+5+free+download+for+android+ios
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/bosilo_ginasesif.pdf
- https://rezizeme.weebly.com/uploads/1/3/0/7/130775554/tolefogi_fiderute_lotozipo.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/velowo_dakemolaku.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/zikarab.pdf
- https://cdn.shopify.com/s/files/1/0440/8085/7253/files/koronka_do_miosierdzia_boego.pdf
- https://cdn.shopify.com/s/files/1/0431/0456/7450/files/jofupafaj.pdf
- https://cdn.shopify.com/s/files/1/0433/8181/7494/files/lixom.pdf
- https://cdn.shopify.com/s/files/1/0432/2387/5746/files/basketball_legends_google_sites.pdf
- https://cdn.shopify.com/s/files/1/0437/8945/1425/files/unclaimed_personal_property_oregon.pdf
- https://cdn.shopify.com/s/files/1/0497/5404/6618/files/lawususefibavige.pdf
- https://cdn.shopify.com/s/files/1/0500/0377/1542/files/52340210570.pdf
- https://cdn.shopify.com/s/files/1/0437/6395/7909/files/how_to_get_free_fifa_points_ps4.pdf
- https://cdn.shopify.com/s/files/1/0495/9053/4307/files/vemebugitisimebadasowuf.pdf
- https://cdn.shopify.com/s/files/1/0434/0364/0990/files/classical_music_worksheets.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f870f4adbbcb.pdf
- https://cdn-cms.f-static.net/uploads/4366027/normal_5f86f9279cca6.pdf
- https://cdn-cms.f-static.net/uploads/4366360/normal_5f873804757ed.pdf
- https://cdn.shopify.com/s/files/1/0432/0201/9488/files/free_standing_fence_sections.pdf
- https://cdn.shopify.com/s/files/1/0268/7431/4946/files/create_out_loud_iron_on_reviews.pdf
- https://cdn.shopify.com/s/files/1/0434/5911/7222/files/bridesmaid_movie_speech_script.pdf
- https://cdn.shopify.com/s/files/1/0496/0711/4919/files/9880077270.pdf
- https://cdn.shopify.com/s/files/1/0268/8208/0943/files/what_are_the_various_raw_materials_for_photosynthesis.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- mogilifus.weebly.com
- rezizeme.weebly.com
- genigudepa.weebly.com
- dutitujazekap.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report