SUSPICIOUS — normal_5f94c5d57f0c2.pdf
SUSPICIOUS — normal_5f94c5d57f0c2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
48da6f4736486bb849f23ebd14e972c8518c3c791d33e90b1edc17346d3ce588 - SHA-1:
f480a0202267845f93f9b9d6d99383ecdb11b0e2 - MD5:
9380958c39f0e76a23fc20da9794903e - ssdeep:
1536:3GF9eQi/bv91xo0uXXHf0Hdkw4sW897D9I:WF9e/XZwyXW897O - TLSH:
T132359DF310E7DC8C7A83AB43ADAB258D5089C74CA1369B5049486B6DC9BC77D7F80A41 - Submitted as: normal_5f94c5d57f0c2.pdf
- File type: pdf · Size: 58303 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=cissp+cbk+fifth+edition+pdf, https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/c124fd.pdf, https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/d96ddb407408.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=cissp+cbk+fifth+edition+pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/c124fd.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/d96ddb407408.pdf
- https://tazejoga.weebly.com/uploads/1/3/1/3/131383942/9570453.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/kodupuru-zipugofuzo-busex-dufafurileponuw.pdf
- https://bafovulik.weebly.com/uploads/1/3/1/0/131070506/rurubewe.pdf
- https://zadumeredevasax.weebly.com/uploads/1/3/1/4/131453870/3402357.pdf
- https://femitinekabel.weebly.com/uploads/1/3/1/4/131437683/ziban.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/golesetixoputafufi.pdf
- https://misikeni.weebly.com/uploads/1/3/4/3/134336029/116070.pdf
- https://uploads.strikinglycdn.com/files/fc386c68-bbff-4a2e-bf7c-f186cf2c725c/wasesosapozezosoxew.pdf
- https://uploads.strikinglycdn.com/files/a46ab88f-e99b-4d2f-93a7-0ea16084e047/66050297056.pdf
- https://uploads.strikinglycdn.com/files/602116b2-ba80-48a9-bf91-e97d69974b3f/jumonunozezigopez.pdf
- https://uploads.strikinglycdn.com/files/3a741133-3f8a-4c98-a0ce-b057126c6ec0/52423613382.pdf
- https://uploads.strikinglycdn.com/files/bbbece84-476f-4718-8a65-c436e042ae64/aquascaping_books.pdf
- https://uploads.strikinglycdn.com/files/7fb4e130-2864-42fd-a7dc-1401f9d40d96/39258674666.pdf
- https://uploads.strikinglycdn.com/files/7fa63740-60b9-4bee-bfb7-61aa8ff41623/podumixar.pdf
- https://uploads.strikinglycdn.com/files/da52189a-9477-41a4-8847-362341d121e4/vuxenijitusuwulo.pdf
- https://uploads.strikinglycdn.com/files/cc8c1f29-2cb8-4b43-8b08-9c521e758cab/49412341912.pdf
- https://cdn.shopify.com/s/files/1/0501/6286/0197/files/terofi.pdf
- https://cdn.shopify.com/s/files/1/0502/7355/0533/files/92315708686.pdf
- https://cdn.shopify.com/s/files/1/0441/0530/2168/files/craftsman_675_lawn_mower_parts.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.link
- jamuseramomuf.weebly.com
- gimejexoxixaza.weebly.com
- tazejoga.weebly.com
- narogigadi.weebly.com
- bafovulik.weebly.com
- zadumeredevasax.weebly.com
- femitinekabel.weebly.com
- wetuxabo.weebly.com
- misikeni.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report