SUSPICIOUS — normal_5f99d4c16e54f.pdf
SUSPICIOUS — normal_5f99d4c16e54f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
802428d709e9d410f9cc9313c1da9873e9d95e9cddf0cc4eebbd4a9d662c0d95 - SHA-1:
56eef8257a17933503824c548bc552e39224046d - MD5:
55d2cd5e503b91119b3747add8e4970f - ssdeep:
768:bgGzpDu1nYcyCIg00ZxJjsXbvEmvMmotFhaIuxLUQ4Z5Lcos3G9MQBciK6aGEjbC:kGFqhoz4FBhZJs3aMQ+BUUlpe - TLSH:
T17C338CF350ABEC4D7FCA9F57ADAA1099A0C9C7482032A680549C767CD4BC5FE3E10961 - Submitted as: normal_5f99d4c16e54f.pdf
- File type: pdf · Size: 48035 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=high+school+musical+play+script+cast, https://cdn.shopify.com/s/files/1/0433/3276/3801/files/gobominerududaxibizefu.pdf, https://cdn.shopify.com/s/files/1/0496/1255/4391/files/mt._angel_school_district.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=high+school+musical+play+script+cast
- https://cdn.shopify.com/s/files/1/0432/2076/2783/files/pleasing_the_ghost_guided_reading_level.pdf
- https://cdn.shopify.com/s/files/1/0433/3276/3801/files/gobominerududaxibizefu.pdf
- https://s3.amazonaws.com/pevuwarobuvowa/laroxomasopigurate.pdf
- https://s3.amazonaws.com/kavitokolezub/monofotobixumodozaziju.pdf
- https://cdn.shopify.com/s/files/1/0496/1255/4391/files/mt._angel_school_district.pdf
- https://cdn-cms.f-static.net/uploads/4366005/normal_5f86f44d77986.pdf
- https://cdn.shopify.com/s/files/1/0497/7813/1095/files/55770251104.pdf
- https://s3.amazonaws.com/sugaguxagu/39625111618.pdf
- https://cdn.shopify.com/s/files/1/0484/1052/5853/files/nanepixugukojiza.pdf
- https://s3.amazonaws.com/gupuso/67728818446.pdf
- https://s3.amazonaws.com/henghuili-files/gosexelugitabena.pdf
- https://s3.amazonaws.com/purufiz/rulojizuzamonovanomuxepab.pdf
- https://cdn.shopify.com/s/files/1/0501/0613/8787/files/7863223676.pdf
- https://cdn.shopify.com/s/files/1/0435/6790/6979/files/xowip.pdf
- https://s3.amazonaws.com/subud/zadodidubisedalifij.pdf
- https://cdn-cms.f-static.net/uploads/4405419/normal_5f92e8bf4d2ff.pdf
- https://cdn.shopify.com/s/files/1/0435/3540/1112/files/pot_belly_stove_parts.pdf
- https://s3.amazonaws.com/zetare/bibliografia_de_un_segun_apa.pdf
- https://cdn-cms.f-static.net/uploads/4367947/normal_5f8768cf236fc.pdf
- https://cdn-cms.f-static.net/uploads/4388173/normal_5f9352e6089eb.pdf
- https://s3.amazonaws.com/paropabaru/retirement_financial_planning.pdf
- https://cdn-cms.f-static.net/uploads/4380682/normal_5f99c4a79b85e.pdf
- https://s3.amazonaws.com/jamokaroxoj/22116468574.pdf
- https://s3.amazonaws.com/figugipopar/xekutetifejofutoj.pdf
Embedded domains
- ttraff.me
- cdn.shopify.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report