SUSPICIOUS — normal_5fa0f2cc7749c.pdf
SUSPICIOUS — normal_5fa0f2cc7749c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
4f0e5018a11f511da36016e5df19c0c6bd5ab272e7226c01902b6c94369b6720 - SHA-1:
26706f5d155faf94bfc5607af7cbc129c4bdb3ea - MD5:
d96b3dd8813f2f4d367150268d89f774 - ssdeep:
768:4gGzpDkoxv4wOXr54jQxaURLM+IM74dZoEYID7Bhg2Ll+yooB9x:VGFgJnnIMEZtY+1W2UhoB9x - TLSH:
T1A5329EF3818BED8CBBC9AF036FAA1159A046D68C7136466058C8773CC47C6EDBD10961 - Submitted as: normal_5fa0f2cc7749c.pdf
- File type: pdf · Size: 44694 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=watch+boruto+episode+73+dubbed, https://uploads.strikinglycdn.com/files/73833b82-9b16-4711-bcb8-ceb6e0ca6e6c/concertmate_990_for_sale.pdf, https://uploads.strikinglycdn.com/files/94945378-b64e-4c92-8292-88133b0ea37c/joxob.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.link/123?keyword=watch+boruto+episode+73+dubbed
- https://s3.amazonaws.com/fokapikow/ncert_11_biology_book_in_hindi.pdf
- https://uploads.strikinglycdn.com/files/73833b82-9b16-4711-bcb8-ceb6e0ca6e6c/concertmate_990_for_sale.pdf
- https://uploads.strikinglycdn.com/files/94945378-b64e-4c92-8292-88133b0ea37c/joxob.pdf
- https://uploads.strikinglycdn.com/files/3ba6dcae-b3b3-445b-9ce0-29f41caf4046/posojofudijib.pdf
- https://cdn.shopify.com/s/files/1/0431/4041/5644/files/mizilomarafu.pdf
- https://s3.amazonaws.com/bidurudilidujug/amplifier_speaker_matching_calculator.pdf
- https://s3.amazonaws.com/jotizifime/tate_no_yuusha_no_nariagari_episode_8.pdf
- https://uploads.strikinglycdn.com/files/4409f037-4854-46f1-83fd-462bfdafdb39/popubilazuk.pdf
- https://s3.amazonaws.com/baxegezivumi/fuguwelekonokoxevo.pdf
- https://cdn.shopify.com/s/files/1/0268/8571/8198/files/69423967397.pdf
- https://uploads.strikinglycdn.com/files/3d868fbf-ed68-4bbd-b0e9-ac22feed4039/sasagewifanaju.pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/5694357.pdf
- https://s3.amazonaws.com/bubodeliza/buffalo_wild_wings_drinks_menu.pdf
- https://s3.amazonaws.com/henghuili-files2/amway_india_products_price_list_2018.pdf
- https://cdn-cms.f-static.net/uploads/4371269/normal_5f8fed820d724.pdf
- https://s3.amazonaws.com/bepukuba/sufuxisevu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- nanorobudilason.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report