SUSPICIOUS — normal_5f8b74b508784.pdf
SUSPICIOUS — normal_5f8b74b508784.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
320fca292a77c8227c3b59d24384b04ffc9c1974caba5c779d4a169640cb5ea9 - SHA-1:
3402858e49e5c8003f647012ac98eb6e1f3d8f18 - MD5:
f2adfd3ffbaa654cfb323ff373b6dec7 - ssdeep:
768:9gGzpDtp1AghXf+7qvSgL5/oNtt8bdCPR1ZytvUtVwBavFoRkYx8wN71zS5:+GFhpL84Ckt4OBwWRki8i1zS5 - TLSH:
T17032AEF7109BDD4C3A869B13BCAB255A914EC68C7236E7641888373C887C1FDAD50A61 - Submitted as: normal_5f8b74b508784.pdf
- File type: pdf · Size: 45209 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=physical+education+pdf+class+12+cbse, https://cdn-cms.f-static.net/uploads/4375076/normal_5f8ae67a82fe8.pdf, https://cdn-cms.f-static.net/uploads/4376099/normal_5f8b73f41cd3a.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=physical+education+pdf+class+12+cbse
- https://cdn-cms.f-static.net/uploads/4375076/normal_5f8ae67a82fe8.pdf
- https://cdn-cms.f-static.net/uploads/4376099/normal_5f8b73f41cd3a.pdf
- https://cdn-cms.f-static.net/uploads/4366661/normal_5f875714c9aa2.pdf
- https://cdn-cms.f-static.net/uploads/4376357/normal_5f8a60b7c58af.pdf
- https://cdn-cms.f-static.net/uploads/4367633/normal_5f87cd5274e02.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f8702fcc7324.pdf
- https://wopuremob.weebly.com/uploads/1/3/2/6/132696580/riwaza.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/5bfe4.pdf
- https://folukufisika.weebly.com/uploads/1/3/1/3/131384255/bokelevofoz-bomofizo-koxug-wasomumuzudim.pdf
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/04ac323ba38.pdf
- https://uploads.strikinglycdn.com/files/02da735e-4023-438d-832a-9f2dff9e55aa/darazil.pdf
- https://uploads.strikinglycdn.com/files/304db439-3b9d-410b-9c77-50c0b3fa4fc8/kijeziwud.pdf
- https://cdn.shopify.com/s/files/1/0482/4268/8154/files/madeas_family_reunion_full_movie_for_free.pdf
- https://cdn.shopify.com/s/files/1/0437/6366/3009/files/fabazirobenobuwidexibiri.pdf
- https://cdn.shopify.com/s/files/1/0427/5293/4044/files/19040660306.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- cdn-cms.f-static.net
- wopuremob.weebly.com
- jezaxegare.weebly.com
- folukufisika.weebly.com
- wefamojugibe.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report