SUSPICIOUS — normal_5f9ec0ba6a254.pdf
SUSPICIOUS — normal_5f9ec0ba6a254.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
117ecbdda02857bbf34654ad998a4096257df6f82f1180752eebd302dbb9ef71 - SHA-1:
4387308b329690aacc33d423784d57633933d09f - MD5:
0088d75e84a1504b8ad98fc37a86aacf - ssdeep:
768:igGzpDgFewpJMdj/6kglpxisLISVtXJqz8FnhgyRY969MyHXH7p:/GF8pBx6KJC8Fhz6mMyX7p - TLSH:
T10A328EF71193ED8C7ECA6F43ADBB11599089C6492226A7A0488C767CC4782FD7F04DA1 - Submitted as: normal_5f9ec0ba6a254.pdf
- File type: pdf · Size: 44350 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=sengoku+bushouki+muramasa+characters, https://cdn.shopify.com/s/files/1/0501/6525/2253/files/god_created_the_integers_free.pdf, https://uploads.strikinglycdn.com/files/69656a79-948c-4a99-b704-9fafb863295a/rofoxizukexaxasosaratuli.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=sengoku+bushouki+muramasa+characters
- https://cdn.shopify.com/s/files/1/0501/6525/2253/files/god_created_the_integers_free.pdf
- https://uploads.strikinglycdn.com/files/69656a79-948c-4a99-b704-9fafb863295a/rofoxizukexaxasosaratuli.pdf
- https://uploads.strikinglycdn.com/files/ee92b1e3-98a5-400a-a819-60777f205858/gukag.pdf
- https://uploads.strikinglycdn.com/files/417a8ddf-0b8e-4fe5-bd94-dfcfa13e3d39/vukagipibujufasobob.pdf
- https://cdn-cms.f-static.net/uploads/4406464/normal_5f9d2b7bdf81b.pdf
- https://cdn.shopify.com/s/files/1/0481/6794/4341/files/91265266957.pdf
- https://uploads.strikinglycdn.com/files/a6586159-a3a8-4fc4-9ed1-52f58c39ffb7/limexivirufipirojafun.pdf
- https://uploads.strikinglycdn.com/files/fb55ca38-0e60-416d-9246-71f3522c78af/15410071897.pdf
- https://uploads.strikinglycdn.com/files/3416ec46-e290-47eb-b63d-33151089b080/37868871638.pdf
- https://cdn.shopify.com/s/files/1/0500/3739/1531/files/baixar_cinebox_remote_apk.pdf
- https://uploads.strikinglycdn.com/files/3427b237-4714-4f63-bfb1-5da73530d4d9/50448536763.pdf
- https://uploads.strikinglycdn.com/files/e712921e-caeb-4ad7-9f1f-f05714cbe835/runescape_fishing_guide_1_99.pdf
- https://uploads.strikinglycdn.com/files/5768575c-ac61-4454-9751-4471c69e5248/43151966723.pdf
- https://cdn-cms.f-static.net/uploads/4386084/normal_5f9124022af73.pdf
- https://cdn.shopify.com/s/files/1/0486/7171/9574/files/7443063614.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report