SUSPICIOUS — normal_5f959b8469be2.pdf
SUSPICIOUS — normal_5f959b8469be2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1211e059a2e72fd6f5593b13dbe7b28080654936985ed5c08186920d8acfa894 - SHA-1:
22a96079e5e634e7b3f944cb5e1c9287e5af2ae6 - MD5:
e2e07ff24ff6ca8279c6714f3b5bddc0 - ssdeep:
768:BgGzpDhptUsnJkTMTyJPc6O7PDUTMBFFUGvnIchZkprGJ2xYucOjOmB0yEHhLfYV:yGFtptc+tPIPdxbc4eHhLfPm - TLSH:
T13032ADF320B7ED4D7A8F5B035EAB119EA08AC289712697A04488332CD0BC5FD7F505A5 - Submitted as: normal_5f959b8469be2.pdf
- File type: pdf · Size: 46307 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=laryngeal+cancer+journal+pdf, https://cdn-cms.f-static.net/uploads/4376379/normal_5f8f48b391083.pdf, https://cdn-cms.f-static.net/uploads/4405641/normal_5f9302a6371cf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=laryngeal+cancer+journal+pdf
- https://cdn-cms.f-static.net/uploads/4376379/normal_5f8f48b391083.pdf
- https://cdn-cms.f-static.net/uploads/4405641/normal_5f9302a6371cf.pdf
- https://cdn-cms.f-static.net/uploads/4371258/normal_5f9489d900217.pdf
- https://cdn-cms.f-static.net/uploads/4384634/normal_5f91f27f0713e.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f8c9b8632cd5.pdf
- https://cdn-cms.f-static.net/uploads/4391920/normal_5f9155ce7cec1.pdf
- https://cdn-cms.f-static.net/uploads/4366346/normal_5f8725f942c13.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f875917a2e6c.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f86f5427ebd0.pdf
- https://cdn.shopify.com/s/files/1/0462/3876/1109/files/mawifos.pdf
- https://cdn.shopify.com/s/files/1/0504/5374/1758/files/17077817770.pdf
- https://cdn.shopify.com/s/files/1/0484/7114/6650/files/dofoxifazaboga.pdf
- https://cdn.shopify.com/s/files/1/0434/6229/5716/files/treat_and_train_manual.pdf
- https://s3.amazonaws.com/jukoxisojow/selenium_java_tutorial.pdf
- https://s3.amazonaws.com/guwutivupudutu/acidose_mtabolique.pdf
- https://s3.amazonaws.com/fizaxo/25958221752.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/1988296.pdf
- https://xinusikavafomi.weebly.com/uploads/1/3/4/3/134353784/4450608.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/32ea35a9d5.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/04609804.pdf
- https://s3.amazonaws.com/levumoduf/kififesanovefikesutupuga.pdf
- https://s3.amazonaws.com/sugaguxagu/12_rights_of_medication_administration.pdf
- https://s3.amazonaws.com/sugaguxagu/fujazegurovuxed.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.cc
- cdn-cms.f-static.net
- cdn.shopify.com
- s3.amazonaws.com
- ditiwudo.weebly.com
- xinusikavafomi.weebly.com
- netaluzubik.weebly.com
- megadezatesaram.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report