SUSPICIOUS — normal_5f88700f1f905.pdf
SUSPICIOUS — normal_5f88700f1f905.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
fbdf6bc8e8335919fcb2a463fb0a4f0dfb8fe7fda7ca195c0bed6f9edac9fc5c - SHA-1:
82ace6ac00420658d8d02150cefd74ab2b519886 - MD5:
a646cd7c4b26056da2fb8f7209cc2e31 - ssdeep:
768:XgGzpDbpFGdW/9sPIM08XZ6zGz4kRsp/pVaNUc7vAQJc5lKR1TgUpPUam+ETyw:wGFfp6m/jGNt2lKR1XZUa1/w - TLSH:
T10E328EF35097ED4CBACBAB439DE711652149C38CA133A790099C6B1CE47C67EBE10960 - Submitted as: normal_5f88700f1f905.pdf
- File type: pdf · Size: 47535 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/123?keyword=beast+mode+soccer+drills+pdf, https://cdn.shopify.com/s/files/1/0430/6049/4485/files/10813245227.pdf, https://cdn.shopify.com/s/files/1/0500/2313/7461/files/dofumakiwisofojotowe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=beast+mode+soccer+drills+pdf
- https://cdn.shopify.com/s/files/1/0430/6049/4485/files/10813245227.pdf
- https://cdn.shopify.com/s/files/1/0500/2313/7461/files/dofumakiwisofojotowe.pdf
- https://cdn.shopify.com/s/files/1/0433/3276/3801/files/41711269371.pdf
- https://cdn.shopify.com/s/files/1/0497/9094/3381/files/rumble_bee_ram_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0438/0786/7037/files/75782615495.pdf
- https://site-1039815.mozfiles.com/files/1039815/nubepuletafixa.pdf
- https://site-1037837.mozfiles.com/files/1037837/5858653157.pdf
- https://site-1039675.mozfiles.com/files/1039675/80039188743.pdf
- https://site-1036874.mozfiles.com/files/1036874/webedukeledudiwifukaxuwo.pdf
- https://uploads.strikinglycdn.com/files/12f0b734-0739-4abb-8156-888a688da352/97580773548.pdf
- https://uploads.strikinglycdn.com/files/a710db77-1c14-43f3-a156-775a3c7fc3da/41914383066.pdf
- https://uploads.strikinglycdn.com/files/9118202a-8685-4c6f-82ff-d02d75a889b2/fivoreterikunurog.pdf
- https://uploads.strikinglycdn.com/files/dec86d91-ab99-4192-aa68-5af3ec94ea34/19004105573.pdf
- https://uploads.strikinglycdn.com/files/72696bd6-7f96-41e2-a681-6e78dfde12de/nomuzidap.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f8736232c151.pdf
- https://cdn-cms.f-static.net/uploads/4366654/normal_5f874a52aabf3.pdf
- https://cdn-cms.f-static.net/uploads/4369333/normal_5f87c0f276fa0.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f86f9d29deb5.pdf
- https://cdn.shopify.com/s/files/1/0434/4256/9368/files/purple_striped_jellyfish.pdf
- https://cdn.shopify.com/s/files/1/0502/7797/4198/files/mobakukemime.pdf
- https://cdn.shopify.com/s/files/1/0435/8363/5619/files/pupetuw.pdf
- https://cdn.shopify.com/s/files/1/0504/3050/9254/files/dewab.pdf
- https://cdn.shopify.com/s/files/1/0483/8929/2184/files/sejinosipa.pdf
- https://site-1039539.mozfiles.com/files/1039539/97014145709.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- site-1039815.mozfiles.com
- site-1037837.mozfiles.com
- site-1039675.mozfiles.com
- site-1036874.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1039539.mozfiles.com
- site-1040878.mozfiles.com
- site-1039754.mozfiles.com
- site-1044240.mozfiles.com
- site-1042729.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report