SUSPICIOUS — normal_5f8a2e5e297c8.pdf
SUSPICIOUS — normal_5f8a2e5e297c8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
f7311d902a39b069fa700dd687b6f51c7b993ed4e927c3d918e80416164a4337 - SHA-1:
5cdb6135afb54af9ffea2c039fff4dcfc82548a7 - MD5:
4379ddf979561c108acc718e200fba15 - ssdeep:
768:OMgGzpDFpNHVXEm1Kfhg99mYim3j2FmEysL0BGsp9modpxMkQ4lYu2Ud8Jtm:GGFhp53mmlGsfmoOkQs12o8Jtm - TLSH:
T198338CF740A7DD8D7A879B43ACB71169648AC349613BE72045CC762DC0BC6BDBE20960 - Submitted as: normal_5f8a2e5e297c8.pdf
- File type: pdf · Size: 48842 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=neighbour+from+hell+android+full, https://uploads.strikinglycdn.com/files/cb0f5334-1276-4741-ab13-3566c964f029/12746778481.pdf, https://uploads.strikinglycdn.com/files/9758b5e0-df73-48db-a390-755cb4a86f94/tofexufolefe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=neighbour+from+hell+android+full
- https://uploads.strikinglycdn.com/files/cb0f5334-1276-4741-ab13-3566c964f029/12746778481.pdf
- https://uploads.strikinglycdn.com/files/9758b5e0-df73-48db-a390-755cb4a86f94/tofexufolefe.pdf
- https://uploads.strikinglycdn.com/files/9fb9560c-22e5-46ce-981a-e330c5bfa5dd/24395637935.pdf
- https://uploads.strikinglycdn.com/files/aa84f2ac-57c8-4329-9b15-8fad25640517/97831387955.pdf
- https://uploads.strikinglycdn.com/files/e20c8313-5bb0-426d-97c2-f3d2343ad414/tobafologapevudisigevekez.pdf
- https://cdn-cms.f-static.net/uploads/4377663/normal_5f8a1e9cae600.pdf
- https://cdn-cms.f-static.net/uploads/4370317/normal_5f88bf9d5351c.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f87143b03372.pdf
- https://uploads.strikinglycdn.com/files/4aba1529-c262-41bb-a195-4b6792faa828/36141501941.pdf
- https://uploads.strikinglycdn.com/files/3316c1f7-e6c6-4c34-bfb8-8c689777b144/42635593968.pdf
- https://uploads.strikinglycdn.com/files/0de4e7bf-c6e5-4564-b14a-6584dd4dd98c/wunezinewu.pdf
- https://uploads.strikinglycdn.com/files/71fb897b-26ef-4897-9806-3603575fe105/tabubowopemevajotave.pdf
- https://cdn.shopify.com/s/files/1/0493/5240/9247/files/56543027432.pdf
- https://cdn.shopify.com/s/files/1/0481/7679/1703/files/mifowezujesarifivikad.pdf
- https://cdn.shopify.com/s/files/1/0493/2406/4927/files/ladder_for_stairs_rental_home_depot.pdf
- https://cdn.shopify.com/s/files/1/0482/8410/6907/files/1_nephi_14_commentary.pdf
- https://uploads.strikinglycdn.com/files/d2278098-902d-46ad-9245-e445c25767dc/72534335508.pdf
- https://uploads.strikinglycdn.com/files/25cf3248-7621-4949-a8c4-4268b5235c1c/ragod.pdf
- https://uploads.strikinglycdn.com/files/2fe3a0a9-269e-448d-9bc6-a53d2f4ba1ee/28338561146.pdf
- https://uploads.strikinglycdn.com/files/a5c0e73f-ec06-46fa-a9a2-b1821a0bd6b5/wunulipov.pdf
- https://zuparimetusu.weebly.com/uploads/1/3/1/3/131378993/dikibavisetelube.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/038885c85ecf8f0.pdf
- https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/bujikuvap.pdf
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/24d786a39f9.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- zuparimetusu.weebly.com
- mojivimimujovo.weebly.com
- mogezisatizate.weebly.com
- sokuvotaboraj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report