SUSPICIOUS — normal_5f8cb8f81a918.pdf
SUSPICIOUS — normal_5f8cb8f81a918.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
481705ea0c441c6fb7a7b3f44ec288064dcc7f86641c99f0b5a6b168b66b6322 - SHA-1:
1bb848af32565355d395df53deb945dd345fc47b - MD5:
d954e7562f87ec5998e3e138d8d51280 - ssdeep:
768:igGzpDcejfbuszNpG5lOZI5fJ/IzU+xHsZnBDZy1xeMfH1zAAl5Z78oLXlPWVcrT:/GF4eN1oA1xeMfH1cArZgoTlP+crT - TLSH:
T11F316BF314ABED8D7A879B03ACBB1519258AD749A232E790459CB72CC4BC67D7F00460 - Submitted as: normal_5f8cb8f81a918.pdf
- File type: pdf · Size: 41101 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=singular+nouns+worksheet+grade+4, https://cdn-cms.f-static.net/uploads/4369776/normal_5f88cb19b1696.pdf, https://cdn-cms.f-static.net/uploads/4370063/normal_5f8aa6ec94f20.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=singular+nouns+worksheet+grade+4
- https://cdn-cms.f-static.net/uploads/4369776/normal_5f88cb19b1696.pdf
- https://cdn-cms.f-static.net/uploads/4370063/normal_5f8aa6ec94f20.pdf
- https://cdn-cms.f-static.net/uploads/4379968/normal_5f8a8bcef2ee6.pdf
- https://cdn-cms.f-static.net/uploads/4368492/normal_5f89e7c4c92dd.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f8713d546492.pdf
- https://cdn-cms.f-static.net/uploads/4367311/normal_5f8740abd412b.pdf
- https://cdn-cms.f-static.net/uploads/4374698/normal_5f896ca0650f9.pdf
- https://cdn-cms.f-static.net/uploads/4385633/normal_5f8cb61b6a4e8.pdf
- https://cdn-cms.f-static.net/uploads/4369911/normal_5f88c0b39f36b.pdf
- https://uploads.strikinglycdn.com/files/41ee60f6-f08d-4379-b882-87379f398616/regafemetowabek.pdf
- https://uploads.strikinglycdn.com/files/c7f61770-18ca-47de-a8b0-425d01e3c8bf/5034327751.pdf
- https://uploads.strikinglycdn.com/files/1d424132-786c-4f3b-8010-6782804344d3/51840903032.pdf
- https://uploads.strikinglycdn.com/files/4dd3389f-f872-4013-ada9-36a775cd3375/1288233696.pdf
- https://uploads.strikinglycdn.com/files/f5ee66a6-597b-43a1-9c32-fac094f20ea4/fabexixezepawujogo.pdf
- https://cdn.shopify.com/s/files/1/0484/9929/4363/files/wuvakikav.pdf
- https://cdn.shopify.com/s/files/1/0495/7175/8232/files/8993071389.pdf
- https://cdn.shopify.com/s/files/1/0496/6721/1428/files/the_el_farol_bar_problem.pdf
- https://cdn.shopify.com/s/files/1/0488/4080/2469/files/14663447372.pdf
- https://cdn.shopify.com/s/files/1/0482/8223/9137/files/blue_nose_pitbull_puppies_for_sale_orlando.pdf
- https://cdn.shopify.com/s/files/1/0484/0095/7608/files/36231387981.pdf
- https://cdn.shopify.com/s/files/1/0482/5740/0994/files/vector_problems_worksheet.pdf
- https://latenenagizogip.weebly.com/uploads/1/3/2/6/132696064/4520508.pdf
- https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/74ae5439bbe84.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- latenenagizogip.weebly.com
- ninukiwipovesot.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report