SUSPICIOUS — normal_5f93d3e016bda.pdf
SUSPICIOUS — normal_5f93d3e016bda.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
55b7482b3d5bc3c2a4d9752310f99d916fdb4a411780f7d2fe67854d2a3239b6 - SHA-1:
8a12b5b691da7668aba987fbcdf75cd3f14ef7ef - MD5:
9b1e00941d032d472d27e25630fb47bc - ssdeep:
768:YgGzpD3XhrxrPeO/baRCcpkVauozoOBHq1FwFDb97m+O16sq75QEUQbZ7mpIT6OT:1GFbw2VaHLBHNDJCF65QEv1i3OQih - TLSH:
T1D034BFF314A7EDCC7EC69B43A9A7016A618EC78C6236A760048C736DD47C6FCAD11860 - Submitted as: normal_5f93d3e016bda.pdf
- File type: pdf · Size: 53785 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.ru/123?keyword=download+game+dragon+world+offline+mod+apk, https://cdn.shopify.com/s/files/1/0505/3045/1628/files/download_apk_whatsapp_mod_iphone_for_android.pdf, https://cdn.shopify.com/s/files/1/0437/3449/9493/files/jubun.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.ru/123?keyword=download+game+dragon+world+offline+mod+apk
- https://cdn.shopify.com/s/files/1/0505/3045/1628/files/download_apk_whatsapp_mod_iphone_for_android.pdf
- https://cdn.shopify.com/s/files/1/0437/3449/9493/files/jubun.pdf
- https://cdn.shopify.com/s/files/1/0496/4142/3012/files/atomic_structure_worksheet_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0478/3210/5119/files/83297666905.pdf
- https://cdn.shopify.com/s/files/1/0462/0150/3897/files/mizefujuwunuzapukobomuj.pdf
- https://cdn.shopify.com/s/files/1/0505/3497/3613/files/fimilo.pdf
- https://s3.amazonaws.com/wovitiku/tafsir_al_quran_al_karim_en_arabe.pdf
- https://s3.amazonaws.com/tapexiw/robert_sapolsky_behave.pdf
- https://s3.amazonaws.com/vexeliku/anti_aesthetic_hal_foster.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/6023986.pdf
- https://lugagixoweliw.weebly.com/uploads/1/3/4/2/134234548/gadonixofi.pdf
- https://gonoloxezejuje.weebly.com/uploads/1/3/1/4/131410007/selez_roronumubazep_lanalubofow.pdf
- https://tunimesepet.weebly.com/uploads/1/3/1/4/131455680/lovezujojejiz-marofefefaka-muputajiwube.pdf
- https://nukubutoti.weebly.com/uploads/1/3/2/3/132302768/79c58012d3eef.pdf
- https://cdn.shopify.com/s/files/1/0481/0352/2467/files/beponivereje.pdf
- https://cdn.shopify.com/s/files/1/0437/6444/9431/files/instagram_blue_tick_keyboard_apk.pdf
- https://cdn.shopify.com/s/files/1/0499/1893/5208/files/numb3rs_activity_energy_answers.pdf
- https://cdn.shopify.com/s/files/1/0493/5231/0943/files/leslie_marmon_silko.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/4056517.pdf
- https://misutinulil.weebly.com/uploads/1/3/1/4/131407711/1184754.pdf
- https://sisaseno.weebly.com/uploads/1/3/0/7/130776680/dojaxa.pdf
- https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/258552.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/0babbd86b6994.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- genigudepa.weebly.com
- lugagixoweliw.weebly.com
- gonoloxezejuje.weebly.com
- tunimesepet.weebly.com
- nukubutoti.weebly.com
- dutitujazekap.weebly.com
- misutinulil.weebly.com
- sisaseno.weebly.com
- moxitasa.weebly.com
- xumogimunosu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report