SUSPICIOUS — normal_5f89840f02f97.pdf
SUSPICIOUS — normal_5f89840f02f97.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
7925c98f5234a9fcb9f981adb0967aacc3eeebac2b90e570a0182993792faab8 - SHA-1:
6fae51902a9530343bcbf361ef6f3695eb321ec1 - MD5:
0e3d3a3513c6e18f482eefb005f0d33a - ssdeep:
768:qhgGzpDrpnVTUKeDCJ5c3mrKV/CFYiv2Ze7MF+Z9g04mUbr5+3Ss:pGF3pQ5CFLKe7k+E0qb1xs - TLSH:
T10B339EF390A7DD9C7E87EB03AEB725286149D78C6236D750448C762C80BC5ADBF11960 - Submitted as: normal_5f89840f02f97.pdf
- File type: pdf · Size: 48194 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=lightroom+cc+free+presets+for+android, https://cdn-cms.f-static.net/uploads/4365600/normal_5f8708887b93a.pdf, https://cdn-cms.f-static.net/uploads/4370064/normal_5f8866cc566be.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=lightroom+cc+free+presets+for+android
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f8708887b93a.pdf
- https://cdn-cms.f-static.net/uploads/4370064/normal_5f8866cc566be.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f8757f41aa85.pdf
- https://uploads.strikinglycdn.com/files/eba0dabe-62b8-401b-a8c1-fcab9fdca632/gejaveta.pdf
- https://uploads.strikinglycdn.com/files/929afdf9-8d94-44a3-8188-4f60395511c3/91675992075.pdf
- https://uploads.strikinglycdn.com/files/39a6a7fe-715f-4110-b7a3-aa9190e9995c/59847730670.pdf
- https://cdn-cms.f-static.net/uploads/4370555/normal_5f88bb878e4ce.pdf
- https://cdn-cms.f-static.net/uploads/4369777/normal_5f893b31ac46f.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f8785db6f2ea.pdf
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f8916cf7e362.pdf
- https://kizekusoviwo.weebly.com/uploads/1/3/1/4/131453028/rivid.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/bewomo.pdf
- https://jarapitoxedomel.weebly.com/uploads/1/3/1/4/131437170/3c827257e.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/fibawubaxavuvabu.pdf
- https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/pivejamu-bariwiroj-jobavurujuzun-kewezofewitimob.pdf
- https://uploads.strikinglycdn.com/files/98f82a35-b56c-4b1d-a562-89620a09693f/92349271016.pdf
- https://uploads.strikinglycdn.com/files/cd417145-5f4f-48f8-b8c2-8b572b908dc9/nuvuxejusunaladax.pdf
- https://uploads.strikinglycdn.com/files/6d781c1a-0586-4de0-829a-acaec15c6480/78213130374.pdf
- https://uploads.strikinglycdn.com/files/122b1ec9-7f78-426d-9cb3-31562d652ab9/77761741752.pdf
- https://uploads.strikinglycdn.com/files/a0a57559-160a-4f04-a094-b1575915a274/24738935967.pdf
- https://uploads.strikinglycdn.com/files/c81eb04e-dcc5-4773-aea4-6243d8451461/kesibizuxiroxinizinuza.pdf
- https://uploads.strikinglycdn.com/files/2a31cc0d-b808-4863-895e-8f6af8165cc6/sabuzixuriputanena.pdf
- https://uploads.strikinglycdn.com/files/c9269226-5df2-4bd3-be9e-020735fb0358/jakepowa.pdf
- https://uploads.strikinglycdn.com/files/e4343b9b-af32-4fdd-bffc-c7f5bee56a94/bovitagikupenag.pdf
Embedded domains
- ttraff.me
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- kizekusoviwo.weebly.com
- bedizegoresupa.weebly.com
- jarapitoxedomel.weebly.com
- keniwuki.weebly.com
- nipufijupetobug.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report