SUSPICIOUS — normal_5f8b3182d3dbb.pdf
SUSPICIOUS — normal_5f8b3182d3dbb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
361e8e7a47516545511636915b7d27e6fc9a743c021662d0389fadd8e299b55d - SHA-1:
7744b7eccf44bbca6c95d0a97415a5f0292dd8db - MD5:
611f2dcdfa94ff04dc63013568c3ae01 - ssdeep:
768:xgGzpDUpq1FrkxnQRBTagCctM8pZbheuwUP0rGdIaFmyu2CW1YdH66N+yquwSP7n:CGF4pqAqxdIaoz2CNdH66N+ruwSPDr4+ - TLSH:
T1D0329EF350E7DD8C2AC79F536DAA0265608AC7896137DB60058C7B6CD1BC1BC6F90950 - Submitted as: normal_5f8b3182d3dbb.pdf
- File type: pdf · Size: 44783 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=wagon+wheel+rug+instructions, https://cdn.shopify.com/s/files/1/0438/1727/1453/files/livibuwetiwap.pdf, https://cdn.shopify.com/s/files/1/0492/9929/2319/files/xfinity_tv_guide_charleston_sc.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=wagon+wheel+rug+instructions
- https://cdn.shopify.com/s/files/1/0438/1727/1453/files/livibuwetiwap.pdf
- https://cdn.shopify.com/s/files/1/0492/9929/2319/files/xfinity_tv_guide_charleston_sc.pdf
- https://cdn.shopify.com/s/files/1/0483/6802/5760/files/baixar_whatsapp_gb_transparente_atualizado_apk.pdf
- https://cdn.shopify.com/s/files/1/0502/8446/2274/files/63260454114.pdf
- https://cdn-cms.f-static.net/uploads/4366040/normal_5f86ffda18907.pdf
- https://cdn-cms.f-static.net/uploads/4370267/normal_5f8977202bba7.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f879d1ece5a2.pdf
- https://cdn-cms.f-static.net/uploads/4369160/normal_5f88d314130eb.pdf
- https://cdn-cms.f-static.net/uploads/4365576/normal_5f895603946f2.pdf
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f870e74c37df.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f87f803e9859.pdf
- https://poxobavu.weebly.com/uploads/1/3/1/4/131453713/67e8167ef4c.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/7206531.pdf
- https://cdn-cms.f-static.net/uploads/4376099/normal_5f8b260a98732.pdf
- https://cdn-cms.f-static.net/uploads/4366623/normal_5f873467937f2.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_5f870636ee6eb.pdf
- https://cdn.shopify.com/s/files/1/0433/9813/5966/files/34575388011.pdf
- https://cdn.shopify.com/s/files/1/0478/4272/1951/files/bernina_1530_inspiration_manual.pdf
- https://cdn.shopify.com/s/files/1/0440/1912/2341/files/62291594803.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ttraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- poxobavu.weebly.com
- jamuseramomuf.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report