SUSPICIOUS — normal_5f8cf9cd26ff0.pdf
SUSPICIOUS — normal_5f8cf9cd26ff0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
3e831c5e60738945aeff4b66642deae6759a546c86ef9f66d96410d1f8849be3 - SHA-1:
b78bb2dddbba4a0f333e9daef07f9c8c0a921cbe - MD5:
2b24492dd54aa5c2eac7d68e2f7eb306 - ssdeep:
768:egGzpD/pJU1avoiRYbyWAWkohdrO7otVq2viqDY6GYjxmF8vkDYs7R:bGFjpMHrO7k7xnjhkDYs7R - TLSH:
T15C329EF75097ED8D2A8AAB479DEA016D250AC7887133976004CC7A3CC47C7BD6F10A62 - Submitted as: normal_5f8cf9cd26ff0.pdf
- File type: pdf · Size: 46762 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=strategic+supplier+relationship+management+pdf, https://cdn.shopify.com/s/files/1/0437/3364/7509/files/25330345572.pdf, https://cdn.shopify.com/s/files/1/0485/9710/6848/files/fepavavebujumoditabu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=strategic+supplier+relationship+management+pdf
- https://cdn.shopify.com/s/files/1/0437/3364/7509/files/25330345572.pdf
- https://cdn.shopify.com/s/files/1/0485/9710/6848/files/fepavavebujumoditabu.pdf
- https://cdn.shopify.com/s/files/1/0483/5940/7765/files/regulation_of_lipid_metabolism.pdf
- https://cdn.shopify.com/s/files/1/0431/6450/0122/files/go_math_assessment_guide_grade_3_common_core_edition.pdf
- https://uploads.strikinglycdn.com/files/93ddfa96-d8e9-4f46-9d74-73d418e70404/tiwozozupa.pdf
- https://uploads.strikinglycdn.com/files/26a86785-0ceb-4c61-8a24-83919e563c06/85744987735.pdf
- https://uploads.strikinglycdn.com/files/6e7d9e68-87fe-4b9b-8913-8977f6bd5324/vanojenozepoxasuza.pdf
- https://cdn-cms.f-static.net/uploads/4368742/normal_5f88684102fa9.pdf
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f87012c147a7.pdf
- https://cdn-cms.f-static.net/uploads/4379848/normal_5f8cb08dc9e20.pdf
- https://cdn-cms.f-static.net/uploads/4367646/normal_5f874bea49c5c.pdf
- https://uploads.strikinglycdn.com/files/1324d0ba-b0ef-4a68-9156-c5c0dcaff015/18146470029.pdf
- https://uploads.strikinglycdn.com/files/f2529b27-b721-4ed4-a99a-e74986f1a709/63289272644.pdf
- https://uploads.strikinglycdn.com/files/3ac31b5b-7cec-4afe-84c3-97d68fa4bb1a/vuzafibom.pdf
- https://uploads.strikinglycdn.com/files/294ece58-fede-4ef6-ace5-06df9de3c1c9/53488713393.pdf
- https://cdn.shopify.com/s/files/1/0439/0099/3691/files/what_are_universities_looking_for.pdf
- https://cdn.shopify.com/s/files/1/0498/2453/0594/files/polajuvopigo.pdf
- https://cdn.shopify.com/s/files/1/0459/9139/5485/files/magul.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report