SUSPICIOUS — normal_5f9064a4bcb19.pdf
SUSPICIOUS — normal_5f9064a4bcb19.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8135a4f477b604901f11a09b695f5acac87ca5d9fd77559962ea43ab40ebfc93 - SHA-1:
b2ffc5f64b8671ec2a812a061c02cd4b827e9d8c - MD5:
9ac8088c70a70e43e75eec532370166a - ssdeep:
768:EgGzpDXp5N26+F8ODSMk4Lqn1xXzx+L01i3WcKDJEh67HZKHTHJ5L:xGFTpPo3DFNLqnnXzxi2imcT8sL - TLSH:
T143309DF35097ED8CBA869F039DE72519558AC3887132A790158CBB6CC4BC6BDBE04861 - Submitted as: normal_5f9064a4bcb19.pdf
- File type: pdf · Size: 38976 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=instructions+not+included+online, https://kuwofepex.weebly.com/uploads/1/3/2/7/132740654/e73d6a239.pdf, https://fufivivol.weebly.com/uploads/1/3/0/8/130873849/givapomezamew.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=instructions+not+included+online
- https://kuwofepex.weebly.com/uploads/1/3/2/7/132740654/e73d6a239.pdf
- https://fufivivol.weebly.com/uploads/1/3/0/8/130873849/givapomezamew.pdf
- https://damijuvik.weebly.com/uploads/1/3/1/3/131381376/1765889.pdf
- https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/f4f2a25313.pdf
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/venemawuj-noxaropuneze-nabadebotisi-susetidor.pdf
- https://cdn.shopify.com/s/files/1/0430/4502/7993/files/what_is_the_origin_of_islamic_education.pdf
- https://cdn.shopify.com/s/files/1/0432/6627/7534/files/4th_grade_multiplying_and_dividing_decimals_worksheets.pdf
- https://s3.amazonaws.com/subud/4th_grade_math_word_problems_with_answers.pdf
- https://s3.amazonaws.com/wonoti/veredimi.pdf
- https://uploads.strikinglycdn.com/files/3b125503-a0d2-461e-a7be-12c8615d1c26/75311377758.pdf
- https://uploads.strikinglycdn.com/files/b0837325-b1c2-4adf-9ea0-3e7972cb0284/punixikek.pdf
- https://uploads.strikinglycdn.com/files/0a18c12f-5b9c-4fb2-8601-083a96cde809/kisuvovorajaji.pdf
- https://uploads.strikinglycdn.com/files/dee78ce7-ea5c-4606-8fe7-854c7b8d3622/mecanica_de_fluidos_y_maquinas_hidraulicas_claudio_mataix_descargar.pdf
- https://pisanofinupu.weebly.com/uploads/1/3/1/4/131437881/kagafataxek.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/disuvuzomajojew-kuvonebokoni-mulepi-wuxexitupo.pdf
- https://ximazula.weebly.com/uploads/1/3/0/7/130738777/zuxezexokomu_jokikin_rajabajota.pdf
- https://risimukino.weebly.com/uploads/1/3/1/3/131383953/9df2bee6d7dd0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.link
- kuwofepex.weebly.com
- fufivivol.weebly.com
- damijuvik.weebly.com
- naxesitigas.weebly.com
- vekejuritikoj.weebly.com
- cdn.shopify.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- pisanofinupu.weebly.com
- dejolezeg.weebly.com
- ximazula.weebly.com
- risimukino.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report