SUSPICIOUS — normal_5f8a95f8cc8cd.pdf
SUSPICIOUS — normal_5f8a95f8cc8cd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6dd4bfc638334d8caadb65c9eaaa87a38e2af3b82416ae6f24dbf3787babfc8a - SHA-1:
5b59740b46b310769c1b8e8f4b82202f9fc1c081 - MD5:
a3dcadd681d99dd24bbac68c972e084e - ssdeep:
768:UFgGzpDxqp5SI+PUBe0BtOJT+WeWEMw58gq6mLHbTuPtE8WQ5Ra54:LGFIpwJExERbKPtE8Ra54 - TLSH:
T125328EF35097ED8C7A8F6F079EAB045C618DC38C6022969454C8372DC4B8AFD3E55A51 - Submitted as: normal_5f8a95f8cc8cd.pdf
- File type: pdf · Size: 44211 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=remove+work+account+android, https://cdn-cms.f-static.net/uploads/4365638/normal_5f87cd0bc4a40.pdf, https://cdn-cms.f-static.net/uploads/4366028/normal_5f886d8dc6979.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=remove+work+account+android
- https://cdn-cms.f-static.net/uploads/4365638/normal_5f87cd0bc4a40.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f886d8dc6979.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f871ad0d138f.pdf
- https://cdn-cms.f-static.net/uploads/4365525/normal_5f876249dab88.pdf
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f871642a249a.pdf
- https://cdn-cms.f-static.net/uploads/4368489/normal_5f8a26106eaca.pdf
- https://cdn-cms.f-static.net/uploads/4367289/normal_5f8908bb70227.pdf
- https://cdn-cms.f-static.net/uploads/4373522/normal_5f88d337e950d.pdf
- https://cdn-cms.f-static.net/uploads/4366642/normal_5f87b0aa68750.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/kekikefuwu.pdf
- https://voxapinave.weebly.com/uploads/1/3/2/7/132740917/jobalajuro_nalikijaliga.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/voranipekaloxuw.pdf
- https://uploads.strikinglycdn.com/files/d6dd523f-203d-4e88-8415-f27239b2dffe/tujetewijizubuxagekogo.pdf
- https://uploads.strikinglycdn.com/files/c686e51c-72e0-4c2f-bcd8-a67eee472ad5/25445560603.pdf
- https://uploads.strikinglycdn.com/files/b0cec247-09f7-45f9-b4f6-c5abcbff7b25/roposudafexi.pdf
- https://uploads.strikinglycdn.com/files/5d6b1101-5616-4cc6-875a-38790b515a15/xuxunorujiru.pdf
- https://uploads.strikinglycdn.com/files/4c102fa4-ba4c-4454-b5c8-69b596ddacf9/fofapunukegajow.pdf
- https://uploads.strikinglycdn.com/files/d9381bb3-bfec-4506-af3d-462a554b16b2/wosiko.pdf
- https://uploads.strikinglycdn.com/files/88582067-5366-4164-be0f-126aa2a63856/39735661522.pdf
- https://uploads.strikinglycdn.com/files/1ae378de-876c-40b8-bb9e-539c9929450e/42564792295.pdf
- https://uploads.strikinglycdn.com/files/272c8796-967a-4e64-9151-880fdbf5649f/paradise_lost_in_plain_english.pdf
- https://uploads.strikinglycdn.com/files/28f91151-43a8-4fa0-9fde-a99456a118af/wibaraluna.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.link
- cdn-cms.f-static.net
- vuxozajuje.weebly.com
- voxapinave.weebly.com
- vilukenuxe.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report