SUSPICIOUS — normal_5f8ab0c22952c.pdf
SUSPICIOUS — normal_5f8ab0c22952c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
40ad4ac1353243cbe958df1e17f7d5520bcb8855e922c9fa27f4093eecf1adf1 - SHA-1:
41c372692cdaa2322ce57a6a10bb3e635630ed5f - MD5:
e700922d1e454457c58549bf093d8806 - ssdeep:
768:qgGzpDmpHn7Gez0bNNwDBYPCt1CgiWCBD/TUaXD4RN+WJOPm0bU9MQRS3HlW:3GFKpHhz0pNQOPr/dXMRNT2me93HlW - TLSH:
T177326DF310E7EC8C7B8AAB1799AB12AE514ED64C612B97A0448C632CD4BC6FD7F00551 - Submitted as: normal_5f8ab0c22952c.pdf
- File type: pdf · Size: 45749 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=session+et+cookies+php+pdf, https://uploads.strikinglycdn.com/files/cebc903a-de1d-4d6e-b520-df2649945076/91452811714.pdf, https://uploads.strikinglycdn.com/files/d9661b95-d3cc-4b1c-a0ef-7bb705bd212e/wisolabaj.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=session+et+cookies+php+pdf
- https://uploads.strikinglycdn.com/files/cebc903a-de1d-4d6e-b520-df2649945076/91452811714.pdf
- https://uploads.strikinglycdn.com/files/d9661b95-d3cc-4b1c-a0ef-7bb705bd212e/wisolabaj.pdf
- https://uploads.strikinglycdn.com/files/dc873c05-5c98-4339-a922-82657e9b2eee/25747427563.pdf
- https://uploads.strikinglycdn.com/files/af786822-830e-4a4e-814c-b221a1e13bbd/xopalarawasefadubav.pdf
- https://uploads.strikinglycdn.com/files/bb407bf4-a67c-48d7-9d63-c5543745f1ed/koduborotufadijige.pdf
- https://uploads.strikinglycdn.com/files/0408f38b-a714-47c8-b314-4b66a77f75fa/39886996509.pdf
- https://uploads.strikinglycdn.com/files/26434ebd-380d-47f3-8dd3-30aaf158e893/69033922757.pdf
- https://uploads.strikinglycdn.com/files/f3170a13-2133-4d3d-810a-38775faaa83b/79424839420.pdf
- https://uploads.strikinglycdn.com/files/ff29b49c-494c-4b3f-9a7d-53f62b20102f/durora.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/5473886.pdf
- https://dumitekajeru.weebly.com/uploads/1/3/0/7/130740207/xajeduxebujebed.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/jokixigaxajax.pdf
- https://berajuvexoru.weebly.com/uploads/1/3/1/8/131860787/xituvisufur.pdf
- https://tegugozitofo.weebly.com/uploads/1/3/0/8/130874592/xebotafilet_xabifu_tewetefib.pdf
- https://uploads.strikinglycdn.com/files/089c88ac-4cc3-4358-93f0-fdca343b05a0/bupujogawifigiwo.pdf
- https://uploads.strikinglycdn.com/files/2015a9a8-5b78-4d7a-9985-739646b5a637/bujiwimalugiwumatazir.pdf
- https://uploads.strikinglycdn.com/files/0340f7d1-2d20-4c48-9b91-4d11e12b5b76/sudivufugov.pdf
- https://uploads.strikinglycdn.com/files/dd952494-482d-454a-a773-3640e9959c24/10668152590.pdf
- https://cdn.shopify.com/s/files/1/0436/1738/6659/files/kentucky_dmv_handbook.pdf
- https://cdn.shopify.com/s/files/1/0493/1957/5718/files/idle_heroes_brave_trial_guide_2020.pdf
- https://cdn.shopify.com/s/files/1/0435/4703/3752/files/td_assurance_auto_contact.pdf
- https://cdn.shopify.com/s/files/1/0483/9050/4599/files/63060710881.pdf
- https://cdn.shopify.com/s/files/1/0482/9331/4722/files/tolejavuxapomuziworebijud.pdf
- https://wavuvavezexa.weebly.com/uploads/1/3/0/7/130775629/d9881f.pdf
Embedded domains
- ttraff.me
- uploads.strikinglycdn.com
- bedizegoresupa.weebly.com
- dumitekajeru.weebly.com
- zoveponezewuda.weebly.com
- berajuvexoru.weebly.com
- tegugozitofo.weebly.com
- cdn.shopify.com
- wavuvavezexa.weebly.com
- waniremupamed.weebly.com
- vefoxetewezelir.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.http
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report