SUSPICIOUS — normal_5f91d11f4204d.pdf
SUSPICIOUS — normal_5f91d11f4204d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
359f5c3fdd44c0ffeb24c58b0abcb929a6563290e1d4ce7f5364efb1289634c9 - SHA-1:
50f76671908c5b1621cbc4df7570e262dcc2ed97 - MD5:
8d1370ac3bb6bc56f7f130cc1c9377da - ssdeep:
768:3gGzpDJppiHv7vGwnx7GRtL066ARVbxmE8fJQTGrS+Wb8ISI:QGFNppAX66ADUTCTlb8ISI - TLSH:
T160308DF350ABEC4C3B8A9B43ADAB2409548AC7896237D7A0448C776CD4BC77D7E50850 - Submitted as: normal_5f91d11f4204d.pdf
- File type: pdf · Size: 35771 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ttraff.club/123?keyword=motorcycle+chain+guide+roller, https://uploads.strikinglycdn.com/files/4fc50c7f-e355-4348-ace8-35e8e4b01424/8804489032.pdf, https://cdn-cms.f-static.net/uploads/4369775/normal_5f889afdcafa4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=motorcycle+chain+guide+roller
- https://s3.amazonaws.com/nezanurugega/gefewefobumagitemi.pdf
- https://s3.amazonaws.com/fajeloninesitel/mukadokimetawokuv.pdf
- https://s3.amazonaws.com/sugaguxagu/11326199346.pdf
- https://s3.amazonaws.com/zirojopemup/78253926301.pdf
- https://uploads.strikinglycdn.com/files/4fc50c7f-e355-4348-ace8-35e8e4b01424/8804489032.pdf
- https://cdn-cms.f-static.net/uploads/4369775/normal_5f889afdcafa4.pdf
- https://cdn-cms.f-static.net/uploads/4382629/normal_5f91965fc49d2.pdf
- https://cdn-cms.f-static.net/uploads/4368222/normal_5f893130f2878.pdf
- https://cdn-cms.f-static.net/uploads/4369518/normal_5f885b05aefb4.pdf
- https://s3.amazonaws.com/kavitokolezub/84204285734.pdf
- https://s3.amazonaws.com/mamukawaxatali/3th_grade_math_word_problems_worksheets.pdf
- https://s3.amazonaws.com/dazutun/feguw.pdf
- https://s3.amazonaws.com/zonivezada/14968331021.pdf
- https://s3.amazonaws.com/kavitokolezub/pilagu.pdf
- https://uploads.strikinglycdn.com/files/1800b4dc-2aa4-407b-b4e8-81b2164f8711/zatodudabulikunijifaropo.pdf
- https://uploads.strikinglycdn.com/files/37c83e64-5131-4f75-b400-70fc5e1595cc/nutuvekarulezejezaluvak.pdf
- https://uploads.strikinglycdn.com/files/f81914f4-ff7e-463b-b74f-e91e97614473/36930904409.pdf
- https://uploads.strikinglycdn.com/files/a8cd1259-1ebb-4152-9d15-7d7be54efa4f/48503422380.pdf
- https://uploads.strikinglycdn.com/files/9f804172-d785-455e-827c-6a92cb73e40a/best_wireless_headphones_2016.pdf
- https://cdn.shopify.com/s/files/1/0483/9420/7381/files/wakalurutugij.pdf
- https://cdn.shopify.com/s/files/1/0467/9955/2663/files/singapore_food_guide_2020.pdf
- https://cdn.shopify.com/s/files/1/0502/8190/6370/files/las_vegas_strip_map.pdf
- https://cdn.shopify.com/s/files/1/0480/1547/4847/files/accessibility_event_android_example.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.club
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report