SUSPICIOUS — normal_5f91f6fe45300.pdf
SUSPICIOUS — normal_5f91f6fe45300.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
3b2e46509f32e1077890f769b70b982a85401d0acf3551e7b3e1a4306e44e91b - SHA-1:
9717cbe91d99ae2558a045276764bd499ee56f6e - MD5:
2fd2bb6e2f01736f47eb65014dedb912 - ssdeep:
768:YgGzpDYpAtV5/iGPiDzMPpe2e+RbUn+1TL5AbOb6I8BGOnCm+tA0rUizVM9k/hf3:1GFMpA3drEG5AbObDlOCBZoizVM9yhf3 - TLSH:
T14F32AEF350A7EC8C3ACA9B07ADAB24695159C3896037DB5098CC376CD4BC1BD7E14A60 - Submitted as: normal_5f91f6fe45300.pdf
- File type: pdf · Size: 45310 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=kingroot+apk+download+latest+version, https://uploads.strikinglycdn.com/files/485bf295-aec1-4722-909c-52a213658ac9/82829296630.pdf, https://uploads.strikinglycdn.com/files/d81f1d00-55e8-41cf-b665-cced052af7d4/89813214913.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=kingroot+apk+download+latest+version
- https://uploads.strikinglycdn.com/files/485bf295-aec1-4722-909c-52a213658ac9/82829296630.pdf
- https://uploads.strikinglycdn.com/files/d81f1d00-55e8-41cf-b665-cced052af7d4/89813214913.pdf
- https://uploads.strikinglycdn.com/files/433e5c36-964e-4ae4-aab1-15878b57b5f4/nujol.pdf
- https://uploads.strikinglycdn.com/files/f8c98979-9868-4d00-b8a8-acf18124d6a2/ronebad.pdf
- https://uploads.strikinglycdn.com/files/9611ace3-5ad8-4a34-88bd-ab3ff539e344/mewutabizabigib.pdf
- https://uploads.strikinglycdn.com/files/2280a7ba-5fe8-4d34-b525-4b70cb72ab00/mumuxigobamununazipenul.pdf
- https://cdn-cms.f-static.net/uploads/4373520/normal_5f88bb8973ec9.pdf
- https://cdn-cms.f-static.net/uploads/4387922/normal_5f91b9d158597.pdf
- https://xigokerurubupa.weebly.com/uploads/1/3/4/3/134312623/69875a5c1cca4.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tifuxasorelav-sunagutigu-gikisifexixabot.pdf
- https://bogadisosupotaj.weebly.com/uploads/1/3/0/7/130776541/bixunosovil.pdf
- https://vabofofed.weebly.com/uploads/1/3/4/3/134337048/sozoxiponiku-duxigagakudaxor-doweke.pdf
- https://cdn.shopify.com/s/files/1/0434/3591/7473/files/ryan-ji_zen_garden.pdf
- https://cdn.shopify.com/s/files/1/0480/7481/7693/files/5_manualidades_faciles_para_vender_o_regalar.pdf
- https://cdn.shopify.com/s/files/1/0484/6845/9670/files/cheat_helix_jump_level_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/lekefuxetupedin.pdf
- https://cdn.shopify.com/s/files/1/0431/8170/3319/files/comment_telecharger_cacaoweb_sur_android.pdf
- https://cdn.shopify.com/s/files/1/0485/8829/2261/files/arabic_grammar_chart.pdf
- https://cdn.shopify.com/s/files/1/0440/1886/0190/files/sizasabuwoxabubedumebi.pdf
- https://cdn.shopify.com/s/files/1/0434/4548/5725/files/recette_thermomix_apritif_dinatoire.pdf
- https://cdn.shopify.com/s/files/1/0483/5973/5456/files/7254790652.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.link
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- xigokerurubupa.weebly.com
- genigudepa.weebly.com
- bogadisosupotaj.weebly.com
- vabofofed.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report