SUSPICIOUS — normal_5f97a341759a0.pdf
SUSPICIOUS — normal_5f97a341759a0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
668e7f1073e20627e74c68a32d56a65e1f4e55f32cb4b04ee90050cd7b22cdae - SHA-1:
56ce6b63d1145d3175845da2f1e75d07bcd0ba12 - MD5:
03dddb135e5385ee15150f1675152427 - ssdeep:
768:ogGzpDZeZ91Gnrp+lurC6hpD1gj+v4OXoTiYdx7HM/y0hHp0UbjK7MMIEA9GHvek:lGFteZ9woTiGBHzAK9A90kvWrrGlCyM - TLSH:
T1B933AEF31067DC8D7A8B9B17ADAA185CB14AC64D61339790148C773CD4BCABCBE20A51 - Submitted as: normal_5f97a341759a0.pdf
- File type: pdf · Size: 51514 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.club/123?keyword=queen+size+electric+blanket, https://cdn-cms.f-static.net/uploads/4375716/normal_5f8a938ce0a12.pdf, https://cdn-cms.f-static.net/uploads/4383925/normal_5f8eb1e0f1851.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=queen+size+electric+blanket
- https://cdn-cms.f-static.net/uploads/4375716/normal_5f8a938ce0a12.pdf
- https://cdn-cms.f-static.net/uploads/4383925/normal_5f8eb1e0f1851.pdf
- https://cdn-cms.f-static.net/uploads/4376086/normal_5f9107724d4b8.pdf
- https://cdn-cms.f-static.net/uploads/4370268/normal_5f8d70bcc4d03.pdf
- https://cdn-cms.f-static.net/uploads/4366003/normal_5f872a5233727.pdf
- https://cdn.shopify.com/s/files/1/0481/5378/8569/files/jowisutivufu.pdf
- https://cdn.shopify.com/s/files/1/0436/9799/5941/files/bixekumojifikeja.pdf
- https://cdn.shopify.com/s/files/1/0266/8586/6177/files/55806698478.pdf
- https://cdn.shopify.com/s/files/1/0266/8560/4017/files/jufaka.pdf
- https://cdn.shopify.com/s/files/1/0428/4874/7676/files/38647787818.pdf
- https://cdn.shopify.com/s/files/1/0502/1673/0799/files/hero_line_wars_starlight_build_guide.pdf
- https://cdn.shopify.com/s/files/1/0481/4694/0065/files/7492114663.pdf
- https://cdn.shopify.com/s/files/1/0434/7337/1300/files/komibamekalawumek.pdf
- https://cdn-cms.f-static.net/uploads/4408348/normal_5f977c14645de.pdf
- https://cdn-cms.f-static.net/uploads/4370529/normal_5f927b857db5e.pdf
- https://s3.amazonaws.com/zesotat/teleological_ethics_definition.pdf
- https://s3.amazonaws.com/fuwawibu/63790296076.pdf
- https://s3.amazonaws.com/bewibiwat/70427760547.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- cdn-cms.f-static.net
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report