SUSPICIOUS — normal_5fa002ecbac65.pdf
SUSPICIOUS — normal_5fa002ecbac65.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
55e6331e548c46f74306623de54ffd9de1272afcbc3ba7b43ab49b6eb7944f80 - SHA-1:
c53adf6316d03b5d29798dae66c127871bb10763 - MD5:
99413defa527b21ce5079877e062083a - ssdeep:
768:RgGzpDmLMgHDFzW03SZOFR2TRqjWAHJITSoSLp2:iGFibc2RQAHJ4GLp2 - TLSH:
T1002F6CF350A7ED8C3A86AF93AEA610986146C64C31639260458C7B2CC4BC6FD7F50D72 - Submitted as: normal_5fa002ecbac65.pdf
- File type: pdf · Size: 33573 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=nellis+afb+campground, https://uploads.strikinglycdn.com/files/7a3c1e9c-6341-4ecd-8c81-206cfe0cf148/40776069955.pdf, https://cdn-cms.f-static.net/uploads/4411501/normal_5f9ef6bfc4286.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=nellis+afb+campground
- https://uploads.strikinglycdn.com/files/7a3c1e9c-6341-4ecd-8c81-206cfe0cf148/40776069955.pdf
- https://cdn-cms.f-static.net/uploads/4411501/normal_5f9ef6bfc4286.pdf
- https://uploads.strikinglycdn.com/files/4e9a3485-0bf8-4e6b-abc1-50d1c102a8e7/mystery_gift_codes_pokemon_x_2019.pdf
- https://uploads.strikinglycdn.com/files/4499d5fa-ff9a-465b-9bda-7cae90d21300/42511892332.pdf
- https://uploads.strikinglycdn.com/files/f194ab86-c363-4d4d-b8d3-4c010cc8ec46/sixenedusufeture.pdf
- https://uploads.strikinglycdn.com/files/17630149-4435-4f0e-a4f4-8f8c1c5352f3/mini_cooper_r57_service_manual.pdf
- https://s3.amazonaws.com/bugutaj/ganufirubu.pdf
- https://uploads.strikinglycdn.com/files/5fa6b063-f516-48da-a0e6-9bc817c80c42/pefasupidazulivexekanez.pdf
- https://uploads.strikinglycdn.com/files/8c9203b8-cfa2-4dc6-922f-3906c70163d1/kuril_islands_map.pdf
- https://cdn.shopify.com/s/files/1/0431/8229/3151/files/les_sceptiques_grecs.pdf
- https://uploads.strikinglycdn.com/files/d0e0039f-51c3-4115-af35-de10f326476a/sagomutiruxamadagef.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- nellislife.com
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report