SUSPICIOUS — normal_5f8a50dd36881.pdf
SUSPICIOUS — normal_5f8a50dd36881.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
66201c79361ecd63e9e120e2e6e5c32c7641e23a82d9b1137e14a8bb34b05a66 - SHA-1:
1692f9681fac753b7b965891d1d68b47d921a83b - MD5:
6f02150f97a1fb7b8b5102cc877861ea - ssdeep:
768:IgGzpDJpVsJbAYgCBrWfzjmWdtByHNF8zd7cgh19fda9GfWtWyW0/Ul6hQPrdHgR:FGFlpVsGNCBybjmWdoE7b4gqWyW70QPE - TLSH:
T150329DF34063ED8D778E9F03AEAB1159504AC38D61269BA051CC372CD4BCABE6E40A51 - Submitted as: normal_5f8a50dd36881.pdf
- File type: pdf · Size: 47092 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.club/123?keyword=sims+3+apk+mod+download, https://uploads.strikinglycdn.com/files/092ceb31-287f-4754-a83d-4318015a0321/13523059776.pdf, https://uploads.strikinglycdn.com/files/ed1df642-0483-4a7d-ba17-3f6a7b05fb35/66965889002.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=sims+3+apk+mod+download
- https://uploads.strikinglycdn.com/files/092ceb31-287f-4754-a83d-4318015a0321/13523059776.pdf
- https://uploads.strikinglycdn.com/files/ed1df642-0483-4a7d-ba17-3f6a7b05fb35/66965889002.pdf
- https://uploads.strikinglycdn.com/files/c425b2c2-cd1d-46a2-a950-459d84d18cba/33341563651.pdf
- https://uploads.strikinglycdn.com/files/35268f07-7550-4556-913e-94c2546569ef/22489079871.pdf
- https://cdn.shopify.com/s/files/1/0500/2743/0059/files/75021455647.pdf
- https://cdn.shopify.com/s/files/1/0481/3950/1735/files/67531229321.pdf
- https://cdn.shopify.com/s/files/1/0465/2384/2718/files/3395827496.pdf
- https://cdn.shopify.com/s/files/1/0432/0352/6820/files/android_mail_app_not_syncing_hotmail.pdf
- https://cdn.shopify.com/s/files/1/0486/3728/0414/files/simile_or_metaphor_worksheet.pdf
- https://uploads.strikinglycdn.com/files/11e8e8d7-fdac-4aa7-8dc9-16dbec214e17/95777194002.pdf
- https://uploads.strikinglycdn.com/files/d64d4b35-a5b1-4054-87ca-3cbd96ff7ad5/7658961502.pdf
- https://uploads.strikinglycdn.com/files/5c08e43c-9b57-43b3-a947-8ba411801f2b/29346885161.pdf
- https://uploads.strikinglycdn.com/files/8c6a14b7-a361-4e6f-b734-321d0fc9940b/dekinisojevap.pdf
- https://cdn.shopify.com/s/files/1/0499/5819/1272/files/willamette_weekly_voter_guide.pdf
- https://cdn.shopify.com/s/files/1/0493/6210/8582/files/30280097448.pdf
- https://cdn.shopify.com/s/files/1/0432/6214/8763/files/madden_mobile_cheats_no_survey_2020.pdf
- https://cdn.shopify.com/s/files/1/0485/0899/3691/files/nedagiribatap.pdf
- https://cdn.shopify.com/s/files/1/0500/4263/4403/files/senses_worksheets_for_kindergarten.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kadupe_ripovu_jozovagazemewe.pdf
- https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/5580598.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/batagebexi.pdf
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/3408965.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.club
- uploads.strikinglycdn.com
- cdn.shopify.com
- gimejexoxixaza.weebly.com
- mogezisatizate.weebly.com
- mojivimimujovo.weebly.com
- vekejuritikoj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report