SUSPICIOUS — normal_5f8f326d9a70c.pdf
SUSPICIOUS — normal_5f8f326d9a70c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
0eb6b745c98b5ac3517af4c19ca218745cf0ddea53935df9d2937afe36e499c7 - SHA-1:
7d6533e2f1219d55adbd5dc47432131bbdb21daf - MD5:
4e87ffa1d8231d452c45c363aa874540 - ssdeep:
3072:IFEpormnEmtlxnPM36ihm3MgWL06ovI9MI:AWormnnJmm3JWLvF - TLSH:
T1CF3AE1F301A3FD0C7E4B6B139EB311A86589D68D61334B6016C8B31DD57CAEC6D20A65 - Submitted as: normal_5f8f326d9a70c.pdf
- File type: pdf · Size: 99689 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=total+war+warhammer+2+lizardmen+unit+guide, https://uploads.strikinglycdn.com/files/c5351e0f-b082-4dbe-8953-2f2d63a3900e/77603096386.pdf, https://uploads.strikinglycdn.com/files/e28963e4-c506-412b-8b20-814c045772c6/45516397281.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=total+war+warhammer+2+lizardmen+unit+guide
- https://uploads.strikinglycdn.com/files/c5351e0f-b082-4dbe-8953-2f2d63a3900e/77603096386.pdf
- https://uploads.strikinglycdn.com/files/e28963e4-c506-412b-8b20-814c045772c6/45516397281.pdf
- https://uploads.strikinglycdn.com/files/531e3645-1273-4378-9ea2-6b2608029898/49969197865.pdf
- https://uploads.strikinglycdn.com/files/7572a587-db97-47bf-a963-10d34b30c374/12520248303.pdf
- https://s3.amazonaws.com/memul/memipefikopimukolus.pdf
- https://finazodaxuvoj.weebly.com/uploads/1/3/2/6/132682535/xorafe_poxakovafa_sikalopedolozig.pdf
- https://fanawilixu.weebly.com/uploads/1/3/1/4/131408209/2183818.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/eaafb29ddf2bb1.pdf
- https://cdn.shopify.com/s/files/1/0492/2939/8182/files/one_piece_online_games_for_pc.pdf
- https://cdn.shopify.com/s/files/1/0268/8240/8644/files/15134679968.pdf
- https://cdn.shopify.com/s/files/1/0486/6424/8470/files/jikunelolowesenavide.pdf
- https://cdn.shopify.com/s/files/1/0427/4061/3286/files/gartner_bi_magic_quadrant_2020.pdf
- https://cdn.shopify.com/s/files/1/0433/2408/0282/files/income_tax_payment_receipt.pdf
- https://cdn-cms.f-static.net/uploads/4374013/normal_5f88d0d8294d4.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f893d6a77291.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f8a4f6c1d1f7.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f8e6e0770008.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f8a205a0fba8.pdf
- https://uploads.strikinglycdn.com/files/2e7edeb2-f3df-48ec-834a-cd3814e84407/dajatezopofixezu.pdf
- https://uploads.strikinglycdn.com/files/fad7bb30-33bf-4619-9f37-6811c7543003/duzemus.pdf
- https://uploads.strikinglycdn.com/files/b3e1a4e4-d7c3-4a2f-bcb9-16b693b87893/kosujowipisajudo.pdf
- https://uploads.strikinglycdn.com/files/4dccdcff-cf7b-43f1-8ffc-8b63671218c5/goxagekeja.pdf
- https://uploads.strikinglycdn.com/files/c19756e9-14c4-46a7-8a65-9b3c55702a30/judaduniw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.link
- uploads.strikinglycdn.com
- s3.amazonaws.com
- finazodaxuvoj.weebly.com
- fanawilixu.weebly.com
- jezaxegare.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report