SUSPICIOUS — normal_5f8b5ad3a04f6.pdf
SUSPICIOUS — normal_5f8b5ad3a04f6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
7c26a42b0e9fea206c08dc7031882f74f22c681b59aa3c2033dc860eaacc1a4a - SHA-1:
f78052acb0e38a46ffa2431246105abf4bf76d2b - MD5:
3fca01fcfd21c8c265deaa5a3c7d8b5d - ssdeep:
768:VgGzpDopP66yzvawFpqdPeG8Ux6DQciGgN0FbQfxea1qdA2+q1ngY:GGFUpy8Sw6bmybQfxzqO2+sngY - TLSH:
T1AB329EF75097DD4C3A82AB47A9FA01A9918AC78C3237E760548C776DC4BC5BCAE10D60 - Submitted as: normal_5f8b5ad3a04f6.pdf
- File type: pdf · Size: 44569 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/123?keyword=manuale+di+cultura+generale+pdf+gratis, https://uploads.strikinglycdn.com/files/a5962a2b-3a86-4d1e-80b3-4c5e0aace984/11821323924.pdf, https://uploads.strikinglycdn.com/files/266bd515-4573-49ef-801b-535dc2e98ad6/romagixojizejenomofireb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=manuale+di+cultura+generale+pdf+gratis
- https://uploads.strikinglycdn.com/files/a5962a2b-3a86-4d1e-80b3-4c5e0aace984/11821323924.pdf
- https://uploads.strikinglycdn.com/files/266bd515-4573-49ef-801b-535dc2e98ad6/romagixojizejenomofireb.pdf
- https://uploads.strikinglycdn.com/files/5c26247b-4e90-4c5b-9b01-c00f224d9afb/933888621.pdf
- https://uploads.strikinglycdn.com/files/b7c6759f-c89b-41d9-9c2e-dfe6a3a2f541/rovorufabixulolasopi.pdf
- https://uploads.strikinglycdn.com/files/233d0a97-1aad-46ef-8f76-3a5ea970fcdc/vekapumibotumidiripovuvel.pdf
- https://uploads.strikinglycdn.com/files/2584b49c-afd0-4d01-934a-2bd7827bae26/60590311811.pdf
- https://uploads.strikinglycdn.com/files/e1ebd986-6b72-4cfb-9b62-f089fd4081ed/23694919225.pdf
- https://uploads.strikinglycdn.com/files/51d6248f-2bdd-42be-a069-19e92b89079f/vorukuxowevafufolazilu.pdf
- https://worobewunit.weebly.com/uploads/1/3/1/4/131406731/251b245ff9b5.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/bekalan.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/5d6b7774f0df7.pdf
- https://cdn-cms.f-static.net/uploads/4370543/normal_5f8b0b4a6f0dd.pdf
- https://cdn-cms.f-static.net/uploads/4366662/normal_5f8a6bc3e151d.pdf
- https://cdn-cms.f-static.net/uploads/4367667/normal_5f8aaabd66dd7.pdf
- https://cdn.shopify.com/s/files/1/0495/5255/6184/files/27807444273.pdf
- https://cdn.shopify.com/s/files/1/0497/4500/2657/files/3_types_of_matter_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0492/9866/9727/files/lovukirogun.pdf
- https://cdn.shopify.com/s/files/1/0481/2754/1409/files/36881034402.pdf
- https://cdn.shopify.com/s/files/1/0482/7424/3748/files/jean_baptiste_colbert_show.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/nodimakovej_xosukukaleropo.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/ac115b69bda4.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.com
- uploads.strikinglycdn.com
- worobewunit.weebly.com
- genigudepa.weebly.com
- walijogopabo.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- besiwalufeg.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report