SUSPICIOUS — normal_5f8ece47050fe.pdf
SUSPICIOUS — normal_5f8ece47050fe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
74dd3b7a7e1f0307bc8b49e072597cbeeaacb22918def389c6b9c9bf1c44e258 - SHA-1:
bb9bf91e39532902927feb361a8fa95f59dc98bf - MD5:
77e160662cc15ce6914c124b7ba410a5 - ssdeep:
768:+DgGzpDOpOrd9yxQ7AdkgUgytSvh0tBpofxmw1nnHlWymLix2QErTE7c5PcLtHMd:LGF6pKXTZtS4poxVHgymkErTE7c5UxHU - TLSH:
T16532AEF754A7ED8C7A8A6B13EDF70954224DC3486236A7A0448C772DD07C6BE7E10960 - Submitted as: normal_5f8ece47050fe.pdf
- File type: pdf · Size: 47494 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/123?keyword=year+7+english+worksheets+pdf+with+answers, https://uploads.strikinglycdn.com/files/683e7aef-d8dd-4f19-84c3-5f6f7a630873/14045194875.pdf, https://uploads.strikinglycdn.com/files/dbca9a8c-bf11-4507-8241-c0c29102d6d5/rizevasoduxupifu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=year+7+english+worksheets+pdf+with+answers
- https://uploads.strikinglycdn.com/files/683e7aef-d8dd-4f19-84c3-5f6f7a630873/14045194875.pdf
- https://uploads.strikinglycdn.com/files/dbca9a8c-bf11-4507-8241-c0c29102d6d5/rizevasoduxupifu.pdf
- https://uploads.strikinglycdn.com/files/276df890-587a-4e0a-b5ac-e10fd34b384b/qualitative_data_analysis_miles_huberman_download.pdf
- https://uploads.strikinglycdn.com/files/1d7e5e9d-4a4b-47b0-ba18-3e35599a11a0/kiwuzopezobizekozirewutuf.pdf
- https://uploads.strikinglycdn.com/files/a341f112-00f2-46d4-9780-ee98305660c7/35700963176.pdf
- https://uploads.strikinglycdn.com/files/9ceb41a4-7c61-4fba-9671-79f3c1e3e1ac/latakudolaziborufofipeno.pdf
- https://uploads.strikinglycdn.com/files/2ce91db9-3e99-4d54-bd30-3a56cc81064f/1902211660.pdf
- https://uploads.strikinglycdn.com/files/a42ac02c-e0cb-48d1-a9d2-b7cdd8584c2f/mevawajixo.pdf
- https://uploads.strikinglycdn.com/files/1e36bcb4-2d90-4caf-ad0b-e5598a0968c3/gta_san_andreas_apk_data_zip.pdf
- https://uploads.strikinglycdn.com/files/f8f9bfa9-a041-4c80-87b7-9c52c7d42b55/39463853389.pdf
- https://uploads.strikinglycdn.com/files/4fe970e6-ce8b-4eae-a0fb-7099f162968c/kurofepumubu.pdf
- https://uploads.strikinglycdn.com/files/419678a4-a559-4cde-a869-bdde7d6d8fff/salewawimusak.pdf
- https://uploads.strikinglycdn.com/files/38668f7b-3d7a-4b66-ac90-7036b6082d10/89148916085.pdf
- https://uploads.strikinglycdn.com/files/99af7138-f92d-4dae-8c80-d685b010ed3e/56384554686.pdf
- https://uploads.strikinglycdn.com/files/03a920e7-60c0-4a5d-a2b5-624eceb18e8d/46857995312.pdf
- https://cdn-cms.f-static.net/uploads/4370528/normal_5f8b9eb67eeb5.pdf
- https://cdn-cms.f-static.net/uploads/4389824/normal_5f8df582d81e0.pdf
- https://cdn-cms.f-static.net/uploads/4369499/normal_5f8a4791123c4.pdf
- https://cdn-cms.f-static.net/uploads/4370746/normal_5f8914056599d.pdf
- https://uploads.strikinglycdn.com/files/3b2b02c0-7017-440e-9d5d-2f0bfa619f70/26375409447.pdf
- https://uploads.strikinglycdn.com/files/6402c57d-5137-42c3-86df-08c1d2651ff5/nifepuzijenaxibapima.pdf
- https://uploads.strikinglycdn.com/files/62b002eb-6b19-4110-81c0-57f7bc872d75/36644508501.pdf
- https://uploads.strikinglycdn.com/files/b4db59de-bb1a-4d2e-94e6-31f4718d2128/66914998491.pdf
- https://uploads.strikinglycdn.com/files/c325cf0f-1715-4b71-aeb8-4f76c7f7a608/zefimizovunesamupojevebu.pdf
Embedded domains
- ttraff.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report