SUSPICIOUS — normal_5f9342db1a1a1.pdf
SUSPICIOUS — normal_5f9342db1a1a1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
8093f426103a8f5af47b674db10ceb7f4e46e41e46aaf458c97ca7079024bea0 - SHA-1:
cfbcc5886bc80b153c5379916893abf8e687076c - MD5:
e312a1d8514a10358a3b2d811d634624 - ssdeep:
768:28gGzpDGAX1GPBxzte2IBrEZBNoiBR/KL5MyEvRHtNQdx9S0ItLq+uQ0zbhrH9CQ:CGFKAknBZKLWXiYDwLJfhrEmAgWX4D - TLSH:
T1A333AEF340A7EC8C3D86AB57AEAB14565489C34D6137D794488C7B6CE4BC5BDBE00821 - Submitted as: normal_5f9342db1a1a1.pdf
- File type: pdf · Size: 51034 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=locate+lost+android+phone+verizon, https://uploads.strikinglycdn.com/files/2f8b4ee0-ae32-4994-abfe-765a8717c830/76331115793.pdf, https://uploads.strikinglycdn.com/files/e04be2f9-5d90-4dd3-8428-61b588147fcd/mazilul.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=locate+lost+android+phone+verizon
- https://uploads.strikinglycdn.com/files/2f8b4ee0-ae32-4994-abfe-765a8717c830/76331115793.pdf
- https://uploads.strikinglycdn.com/files/e04be2f9-5d90-4dd3-8428-61b588147fcd/mazilul.pdf
- https://uploads.strikinglycdn.com/files/a4b6517b-4be2-413d-b491-27a9a5c44bb0/zuzubin.pdf
- https://uploads.strikinglycdn.com/files/15eaa8bd-8729-4df1-b13e-df0d41b20b04/10851420181.pdf
- https://s3.amazonaws.com/saziwijaxodav/zasonorupiwujovenesefir.pdf
- https://s3.amazonaws.com/bisute/analog_science_fiction_and_fact.pdf
- https://s3.amazonaws.com/henghuili-files2/vitigedejekezadewanig.pdf
- https://s3.amazonaws.com/vuraradaso/wizib.pdf
- https://cdn.shopify.com/s/files/1/0268/7995/1018/files/59848774341.pdf
- https://cdn.shopify.com/s/files/1/0502/7853/1255/files/46878575844.pdf
- https://cdn.shopify.com/s/files/1/0268/8345/7197/files/manuale_inverter_allen_bradley_160.pdf
- https://cdn.shopify.com/s/files/1/0440/8901/6472/files/60024740923.pdf
- https://cdn.shopify.com/s/files/1/0268/7156/2438/files/better_length_hair.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f8718114419c.pdf
- https://cdn-cms.f-static.net/uploads/4380528/normal_5f922b0fc883a.pdf
- https://cdn-cms.f-static.net/uploads/4365636/normal_5f86fb103acdd.pdf
- https://s3.amazonaws.com/sugaguxagu/zefiwofafuze.pdf
- https://s3.amazonaws.com/xanebavifamopez/kptcl_recruitment_2019_notification_in_kannada.pdf
- https://s3.amazonaws.com/nowokil/dojevezuj.pdf
- https://s3.amazonaws.com/zunaduxa/bowixisikawo.pdf
- https://s3.amazonaws.com/fatikonavori/73093241986.pdf
- https://s3.amazonaws.com/jeduzizonox/budget_allocation_in_ethiopia.pdf
- https://s3.amazonaws.com/jijumupade/wopabapoxilarijoregupitud.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.link
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report