SUSPICIOUS — normal_5f8c0f46e8007.pdf
SUSPICIOUS — normal_5f8c0f46e8007.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
42704a7c70a6a1d11fd7e2e2a97d65cf463e929e77ae9f40fa828f01e0875eaa - SHA-1:
62647315dd2b11174779e4b58cbc3f592fa26163 - MD5:
1ab4d2ba148db5df2f0a3281fbcd16ea - ssdeep:
768:9ggGzpD4eViX1x+Py+2WNmOeTwa782vS14UTlYWQxnuZ9uM1qqFM2/zrnHz0cwut:XGFkeC8142lon4qU5brHwcwuOmlP37k+ - TLSH:
T143328EF34097ED8C7787AB039DAB11656089C34D6232EBA0458CB72CC5BC5BDBE518A1 - Submitted as: normal_5f8c0f46e8007.pdf
- File type: pdf · Size: 45895 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/123?keyword=ps4+remote+play+android+tv+apk, https://cdn.shopify.com/s/files/1/0483/2899/9065/files/16446942079.pdf, https://cdn.shopify.com/s/files/1/0483/0612/7003/files/mogilesotuxafuzoketifesol.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.com/123?keyword=ps4+remote+play+android+tv+apk
- https://cdn.shopify.com/s/files/1/0483/2899/9065/files/16446942079.pdf
- https://cdn.shopify.com/s/files/1/0483/0612/7003/files/mogilesotuxafuzoketifesol.pdf
- https://cdn.shopify.com/s/files/1/0477/1489/3980/files/rise_of_napoleon_game.pdf
- https://cdn.shopify.com/s/files/1/0483/9784/4637/files/2_player_tank_battle_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0501/5987/8320/files/fcl_and_lcl.pdf
- https://cdn.shopify.com/s/files/1/0500/4538/6902/files/52377162673.pdf
- https://cdn.shopify.com/s/files/1/0488/1527/6197/files/quotes_from_catcher_in_the_rye_about_isolation.pdf
- https://cdn.shopify.com/s/files/1/0427/8868/3932/files/equipo_de_trabajo_en_ingles.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/72d7dd03fbce46b.pdf
- https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/8376456.pdf
- https://tugajepefur.weebly.com/uploads/1/3/1/4/131453805/zupebowelupepavetin.pdf
- https://vozunutav.weebly.com/uploads/1/3/0/9/130969695/kubojakefuji.pdf
- https://fanavepuru.weebly.com/uploads/1/3/1/8/131871984/130c1.pdf
- https://pesajupamobe.weebly.com/uploads/1/3/1/6/131607203/rudejonof.pdf
- https://cdn-cms.f-static.net/uploads/4367927/normal_5f884177a82fc.pdf
- https://cdn-cms.f-static.net/uploads/4369502/normal_5f887ec1e7764.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f873901263d6.pdf
- https://cdn-cms.f-static.net/uploads/4379855/normal_5f8b360716b94.pdf
- https://cdn-cms.f-static.net/uploads/4380876/normal_5f8af97706686.pdf
- https://cdn-cms.f-static.net/uploads/4383160/normal_5f8b72b2bc753.pdf
- https://cdn-cms.f-static.net/uploads/4367279/normal_5f8a22e66b96d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.com
- cdn.shopify.com
- besiwalufeg.weebly.com
- vixijusodu.weebly.com
- tugajepefur.weebly.com
- vozunutav.weebly.com
- fanavepuru.weebly.com
- pesajupamobe.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report