SUSPICIOUS — normal_5f8869827f35d.pdf
SUSPICIOUS — normal_5f8869827f35d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f37452c6982447a69956b7015497416af571479b1a11ad448a04d7fdc5efb9f9 - SHA-1:
589e79022383b2ae24a0c47df9bd8d84e833cd1d - MD5:
879d7fec068c73ba067ba755f1730d10 - ssdeep:
768:RgGzpD1eqOq2sRcRwbVzI8aS3qcg7lRB956lqwDpjqBAnFsg5loFCMxWEW5HzL+h:iGFheUg794kBHg/wrxWEW5HH+a42YZ - TLSH:
T178349EF340ABCD8D368BEB536DBB1059614AC78861329B544489677CC87C2BDBF10AA1 - Submitted as: normal_5f8869827f35d.pdf
- File type: pdf · Size: 57314 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=radhe+radhe+mp3+song+wapking, https://cdn.shopify.com/s/files/1/0492/2962/7548/files/6999397743.pdf, https://cdn.shopify.com/s/files/1/0497/9851/2803/files/imagitarium_automatic_fish_feeder_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=radhe+radhe+mp3+song+wapking
- https://cdn.shopify.com/s/files/1/0492/2962/7548/files/6999397743.pdf
- https://cdn.shopify.com/s/files/1/0497/9851/2803/files/imagitarium_automatic_fish_feeder_manual.pdf
- https://cdn.shopify.com/s/files/1/0479/6973/0723/files/tamarizagib.pdf
- https://cdn.shopify.com/s/files/1/0497/6174/7105/files/31297804421.pdf
- https://cdn.shopify.com/s/files/1/0500/6268/8427/files/work_permit_application_form_thailand.pdf
- https://cdn.shopify.com/s/files/1/0432/0215/0557/files/ford_focus_c_max_2005_owners_manual.pdf
- https://cdn.shopify.com/s/files/1/0428/6201/8716/files/rukusixusurireso.pdf
- https://cdn.shopify.com/s/files/1/0481/4097/6295/files/instructions_meaning_in_programming.pdf
- https://uploads.strikinglycdn.com/files/47552fdd-818c-4fff-87f9-f5dafc291a39/sekuvamar.pdf
- https://uploads.strikinglycdn.com/files/cf6c8ccb-ca95-4194-a0cc-fb90c90cadbd/rugomugofubasoj.pdf
- https://uploads.strikinglycdn.com/files/27a065d9-5c79-4007-bed5-eefd73778850/18371767034.pdf
- https://uploads.strikinglycdn.com/files/14a092f6-730f-4932-a258-502214be2d0b/29660904868.pdf
- https://cdn.shopify.com/s/files/1/0493/8432/5305/files/gwinnett_county_school_calendar_15-16.pdf
- https://cdn.shopify.com/s/files/1/0482/5029/0330/files/58906676506.pdf
- https://site-1043698.mozfiles.com/files/1043698/76153850123.pdf
- https://site-1039343.mozfiles.com/files/1039343/ridevinumuremuso.pdf
- https://site-1041682.mozfiles.com/files/1041682/xusesojumebuxeto.pdf
- https://cdn-cms.f-static.net/uploads/4368501/normal_5f88249a749c6.pdf
- https://cdn-cms.f-static.net/uploads/4368244/normal_5f87dce3b976a.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f87052d6cb7d.pdf
- https://cdn-cms.f-static.net/uploads/4368977/normal_5f88172836d8b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1043698.mozfiles.com
- site-1039343.mozfiles.com
- site-1041682.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report