SUSPICIOUS — normal_5f9af03f35703.pdf
SUSPICIOUS — normal_5f9af03f35703.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
3217583fa8b88021158d2ce2a7dac3c03a6acfa7c7caac3cb76c2ac2f430ae55 - SHA-1:
3b334aa4980071a4f9d9d19d3427c6ce2541c4a1 - MD5:
e3177d6411d072c872906d6006eac16a - ssdeep:
768:ygGzpDfXQ2r8kxyMrVk5J8GKWy8WZeK6NGlzPlWTLN1xvDh2JQ/b+E6lyo:vGFzXqTRy8WZeK6Nsz0tLhOQ/Qlyo - TLSH:
T1C531AFF7945BED8C2AC6AB136ED601492559DB8C2122A7B080C8767CC8BC7FD6E50D70 - Submitted as: normal_5f9af03f35703.pdf
- File type: pdf · Size: 40944 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=coca+cola+fundraiser+order+form+2016, https://cdn.shopify.com/s/files/1/0482/2197/8778/files/99271145407.pdf, https://cdn.shopify.com/s/files/1/0503/6087/7224/files/new_guidelines_for_sepsis_2020.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=coca+cola+fundraiser+order+form+2016
- https://cdn.shopify.com/s/files/1/0482/2197/8778/files/99271145407.pdf
- https://cdn.shopify.com/s/files/1/0503/6087/7224/files/new_guidelines_for_sepsis_2020.pdf
- https://uploads.strikinglycdn.com/files/6b72136f-489d-4d33-925f-9bd04589d355/jexiduwusifiverutozazuti.pdf
- https://cdn-cms.f-static.net/uploads/4384164/normal_5f8d607bec483.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f986a93687f5.pdf
- https://cdn-cms.f-static.net/uploads/4368997/normal_5f97df5dbe205.pdf
- https://uploads.strikinglycdn.com/files/83f5abf3-6127-4ed7-b51a-01e48cd6e5a2/14574211579.pdf
- https://cdn-cms.f-static.net/uploads/4386337/normal_5f93b7114bd07.pdf
- https://cdn-cms.f-static.net/uploads/4409619/normal_5f946c334952d.pdf
- https://uploads.strikinglycdn.com/files/e9fdb020-41ba-4130-a661-c95e73a894ee/joronovinejusisuxiwo.pdf
- https://cdn-cms.f-static.net/uploads/4419206/normal_5f9ac12b71c71.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report