SUSPICIOUS — normal_5f90a0e13685c.pdf
SUSPICIOUS — normal_5f90a0e13685c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0d900cffc64afb4222354c643ce50a85d75983c4d30378ffa967ba3b0e83ae3f - SHA-1:
32dd0d576f2f2e092fc88427ea76cb50d32e13fa - MD5:
e06bd233f4e0392c90aa7d32db931738 - ssdeep:
1536:IGFJpZbn+lkzvKt+RIY4qTGrLMqdXWpsRgrg:lFJp9ndTKt+RIYnT4nd6sR/ - TLSH:
T19D348DF351EBEC8D7A8B8B0369AB355D5089E78861328BA0559D777CC0BC27D2E20550 - Submitted as: normal_5f90a0e13685c.pdf
- File type: pdf · Size: 57042 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=castle+tower+defense+2+apk+mod, https://luwobidope.weebly.com/uploads/1/3/0/8/130814225/majizuwisokurut_mirowop.pdf, https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/3739262.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=castle+tower+defense+2+apk+mod
- https://luwobidope.weebly.com/uploads/1/3/0/8/130814225/majizuwisokurut_mirowop.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/3739262.pdf
- https://nurekagenarufab.weebly.com/uploads/1/3/1/6/131636906/1609079.pdf
- https://zosupexaduj.weebly.com/uploads/1/3/0/7/130738593/f7f429ddf6.pdf
- https://wuwuleli.weebly.com/uploads/1/3/1/3/131398564/2276774.pdf
- https://junoxavod.weebly.com/uploads/1/3/1/3/131384771/defeju.pdf
- https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/dunijojivisilezuw.pdf
- https://xijonezamo.weebly.com/uploads/1/3/1/4/131407630/lekupiwuxo.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/fc0d2a8ff57aa9.pdf
- https://cdn-cms.f-static.net/uploads/4366622/normal_5f8a9a1407cdf.pdf
- https://cdn-cms.f-static.net/uploads/4392867/normal_5f8ec5af0d1cb.pdf
- https://cdn-cms.f-static.net/uploads/4388048/normal_5f8ed9593eedc.pdf
- https://cdn-cms.f-static.net/uploads/4379848/normal_5f8d5f4fcfd7e.pdf
- https://cdn-cms.f-static.net/uploads/4371509/normal_5f88bd9ed12b5.pdf
- https://cdn.shopify.com/s/files/1/0483/9368/3104/files/clean_master_no_ads_apk.pdf
- https://cdn.shopify.com/s/files/1/0504/2064/6048/files/nuclear_reactor_simulator.pdf
- https://cdn.shopify.com/s/files/1/0437/5055/5799/files/tea_rose_perfume_ebay.pdf
- https://cdn.shopify.com/s/files/1/0460/6951/4404/files/mujefiroli.pdf
- https://cdn.shopify.com/s/files/1/0488/2854/7237/files/mudosafoxowigazepifug.pdf
- https://s3.amazonaws.com/zetare/labofadokilex.pdf
- https://s3.amazonaws.com/wonoti/26341080714.pdf
- https://s3.amazonaws.com/mijedusovineti/16644819857.pdf
- https://s3.amazonaws.com/subud/51094398608.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.link
- luwobidope.weebly.com
- zimiduninu.weebly.com
- nurekagenarufab.weebly.com
- zosupexaduj.weebly.com
- wuwuleli.weebly.com
- junoxavod.weebly.com
- damijuvik.weebly.com
- xijonezamo.weebly.com
- netaluzubik.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report