SUSPICIOUS — normal_5f968c0577023.pdf
SUSPICIOUS — normal_5f968c0577023.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
767d12774eb1d9257ff3dd655008f4903261ab26e8848c0520a1954a77db6df1 - SHA-1:
775d29e75b2a52094543386db0d8cfca608ca478 - MD5:
55f14d89551af9030291380da843e00a - ssdeep:
768:LgGzpDTpzE6N9TrrZg3l5th6Es9Oirm52KGr34L+k3pE4J/oGUEpeQohtTNSbN90:0GFfp5+g34lLJ/oUEQobTEbD+5AimfS - TLSH:
T128329DF35097FC8D7ACEAB036EAB125E9009C68D612AD66015CC763CD4782FD6E00A52 - Submitted as: normal_5f968c0577023.pdf
- File type: pdf · Size: 47243 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.club/123?keyword=tampax+pearl+user+guide, https://cdn.shopify.com/s/files/1/0504/8034/9344/files/devunikofuzitiwapovajaba.pdf, https://cdn.shopify.com/s/files/1/0484/0541/4045/files/conceptual_framework_diagram.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=tampax+pearl+user+guide
- https://cdn.shopify.com/s/files/1/0504/8034/9344/files/devunikofuzitiwapovajaba.pdf
- https://cdn.shopify.com/s/files/1/0484/0541/4045/files/conceptual_framework_diagram.pdf
- https://cdn.shopify.com/s/files/1/0485/9851/5872/files/wilalepudukowol.pdf
- https://cdn.shopify.com/s/files/1/0434/4456/8220/files/paleo_diet_for_beginners.pdf
- https://cdn.shopify.com/s/files/1/0488/2854/7237/files/experimenting_with_babies.pdf
- https://cdn.shopify.com/s/files/1/0430/0003/7527/files/71115109373.pdf
- https://cdn.shopify.com/s/files/1/0498/1129/2314/files/1000_phrases_in_english.pdf
- https://cdn.shopify.com/s/files/1/0484/7121/2193/files/xefixujole.pdf
- https://cdn.shopify.com/s/files/1/0433/6828/4316/files/mejomawix.pdf
- https://cdn.shopify.com/s/files/1/0479/2113/5783/files/en_route_to_usps_for_induction.pdf
- https://cdn.shopify.com/s/files/1/0429/6153/5132/files/55710759937.pdf
- https://cdn.shopify.com/s/files/1/0468/0312/4375/files/wopew.pdf
- https://cdn.shopify.com/s/files/1/0498/5454/6075/files/media_research_methodology.pdf
- https://cdn.shopify.com/s/files/1/0488/0623/2229/files/7789023970.pdf
- https://cdn.shopify.com/s/files/1/0502/5723/2034/files/lorule_map_hyrule_warriors_guide.pdf
- https://cdn.shopify.com/s/files/1/0431/5768/4385/files/mole_calculations_practice_worksheet.pdf
- https://uploads.strikinglycdn.com/files/be7d6475-58d8-4466-810c-af0062185966/banejevexipejipixipixupi.pdf
- https://uploads.strikinglycdn.com/files/8740a943-a74f-4bb2-8a78-a5755dc4eb16/auditing_and_assurance_services_16th.pdf
- https://nizesuvijeva.weebly.com/uploads/1/3/1/6/131607023/sifuwatodomenad.pdf
- https://rutaluxunenore.weebly.com/uploads/1/3/0/7/130740368/3eae1cee9706f5.pdf
- https://tinalolovini.weebly.com/uploads/1/3/4/3/134371967/zagezigixake.pdf
- https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/lelelozulofesud.pdf
- https://kikuvabafot.weebly.com/uploads/1/3/4/3/134332304/312343.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.club
- cdn.shopify.com
- uploads.strikinglycdn.com
- nizesuvijeva.weebly.com
- rutaluxunenore.weebly.com
- tinalolovini.weebly.com
- moxitasa.weebly.com
- kikuvabafot.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report