SUSPICIOUS — normal_5f8eb11e875e9.pdf
SUSPICIOUS — normal_5f8eb11e875e9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
15640c8486dc95ffe62a02f9ee6497630ba6035333fd2ce9efa5028d8375da93 - SHA-1:
7bcdb1595b2615d88ad0f0f8bfdbdc33e92fe1be - MD5:
71b9d34d8a6b82a8e285956cc2e9e9da - ssdeep:
768:HNgGzpDQpsPCbC6Z3/nOPJG1QnmLeqJR+4oOwe0QJ94egACj5uSG6FwG4W4:OGFEpskJ9w4g3YSG634W4 - TLSH:
T12A328DF354A7ED8C7B4B9B13ADA211956449C788A237EBA0108C271DC4BC6BD3E50D71 - Submitted as: normal_5f8eb11e875e9.pdf
- File type: pdf · Size: 44021 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=pokemon+mega+emerald+gba+download+android, https://cdn-cms.f-static.net/uploads/4371269/normal_5f8d809449ece.pdf, https://cdn-cms.f-static.net/uploads/4379601/normal_5f8eacbe6c2a2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=pokemon+mega+emerald+gba+download+android
- https://cdn-cms.f-static.net/uploads/4371269/normal_5f8d809449ece.pdf
- https://cdn-cms.f-static.net/uploads/4379601/normal_5f8eacbe6c2a2.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f88b65e38dac.pdf
- https://cdn-cms.f-static.net/uploads/4367305/normal_5f895daf6cc51.pdf
- https://cdn-cms.f-static.net/uploads/4379385/normal_5f8d8543d0e46.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/rativokusoralenoj.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/5280686.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/5b300b.pdf
- https://tuxitusonodedin.weebly.com/uploads/1/3/0/8/130873989/2861344.pdf
- https://fanawilixu.weebly.com/uploads/1/3/1/4/131408209/6d9bfcae3eb5.pdf
- https://uploads.strikinglycdn.com/files/0e9fb2e2-9ea9-4cf9-b858-da37a509bf9d/41360283742.pdf
- https://uploads.strikinglycdn.com/files/bde7d60b-3589-42c3-9d78-2b85e2e30d6a/9481186858.pdf
- https://uploads.strikinglycdn.com/files/c587be04-24e6-4cb3-bb42-29a0091b3350/potidanarezosazu.pdf
- https://uploads.strikinglycdn.com/files/2433c773-5102-46ab-b12c-5b4434e2e02f/38184141612.pdf
- https://uploads.strikinglycdn.com/files/139ee35d-7ad9-4cf0-944d-1911a60fc5fd/33403135042.pdf
- https://cdn-cms.f-static.net/uploads/4378623/normal_5f8cb0e71fa2f.pdf
- https://cdn-cms.f-static.net/uploads/4377379/normal_5f8aea783a020.pdf
- https://cdn-cms.f-static.net/uploads/4379046/normal_5f8b4d8177bee.pdf
- https://cdn-cms.f-static.net/uploads/4370791/normal_5f8e6d87b9ff2.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f86f43ac442e.pdf
- https://cdn.shopify.com/s/files/1/0438/7779/3960/files/speech_marks_dialogue_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0478/8905/5910/files/burlington_books_2_eso.pdf
- https://cdn.shopify.com/s/files/1/0483/5940/7765/files/denoising_autoencoder_tutorial.pdf
- https://cdn.shopify.com/s/files/1/0501/5738/7937/files/wilovenuruneloj.pdf
Embedded domains
- ttraff.me
- cdn-cms.f-static.net
- jamuseramomuf.weebly.com
- narogigadi.weebly.com
- besiwalufeg.weebly.com
- tuxitusonodedin.weebly.com
- fanawilixu.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report