SUSPICIOUS — normal_5f98c00347a90.pdf
SUSPICIOUS — normal_5f98c00347a90.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
1f0979aa53a593d97a195dbf8e16a1d81a045211b8b38a2e558c6e6e358f2892 - SHA-1:
8e3d368ad21e511cd1b31e3434c3fc0a05c6e6d6 - MD5:
0e6cf823f63ebac15b3356a3bf31698a - ssdeep:
768:tGgGzpDIpgunCRPqlxnGl5ypzxMLgDeVfgI32XC+DFtK2BIG5e5QwKczO0czQBh:FGFspHfMLgDeJa1H7BIG5e3O0cz0h - TLSH:
T171319FF390ABDC4D7A86AB43ADAA245D6589C38D6132F760048C772CD5BC6BD7E00C61 - Submitted as: normal_5f98c00347a90.pdf
- File type: pdf · Size: 41993 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=oracle+sql+by+example+4th+edition+pdf, https://cdn.shopify.com/s/files/1/0266/8419/5014/files/71651246671.pdf, https://cdn.shopify.com/s/files/1/0503/3777/5810/files/82866244628.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=oracle+sql+by+example+4th+edition+pdf
- https://cdn.shopify.com/s/files/1/0266/8419/5014/files/71651246671.pdf
- https://cdn.shopify.com/s/files/1/0503/3777/5810/files/82866244628.pdf
- https://cdn.shopify.com/s/files/1/0441/3816/8472/files/case_western_tuition_room_and_board.pdf
- https://cdn.shopify.com/s/files/1/0480/1475/3951/files/classification_of_horticultural_crops.pdf
- https://vixalabalu.weebly.com/uploads/1/3/4/3/134396729/4204979.pdf
- https://solujokorox.weebly.com/uploads/1/3/4/1/134108712/xatelogapavajek.pdf
- https://s3.amazonaws.com/lovetijif/kixotovedagikegosojex.pdf
- https://s3.amazonaws.com/fasanag/jopofimubuxuxeli.pdf
- https://cdn.shopify.com/s/files/1/0430/5377/7047/files/supersu_apk_how_to_root.pdf
- https://cdn.shopify.com/s/files/1/0499/4138/1274/files/dabime.pdf
- https://cdn.shopify.com/s/files/1/0432/6627/7534/files/76671001833.pdf
- https://cdn.shopify.com/s/files/1/0435/2317/8656/files/kegunovuvawa.pdf
- https://s3.amazonaws.com/ganubifirigevi/97946337803.pdf
- https://s3.amazonaws.com/dejolavubukugeb/billetes_didacticos_colombianos_para_imprimir.pdf
- https://s3.amazonaws.com/fasanag/fewobinotekuka.pdf
- https://s3.amazonaws.com/ruzumeb/brche_textaufgaben_klasse_6.pdf
- https://nutolifawivu.weebly.com/uploads/1/3/1/4/131437776/1e6340157e2a.pdf
- https://tevumusavobe.weebly.com/uploads/1/3/4/1/134108657/4667346.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- cdn.shopify.com
- vixalabalu.weebly.com
- solujokorox.weebly.com
- s3.amazonaws.com
- nutolifawivu.weebly.com
- tevumusavobe.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report