SUSPICIOUS — normal_5f9a61a466a68.pdf
SUSPICIOUS — normal_5f9a61a466a68.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
8378d6b364057b24a60241656501bde91a8501432de2c019a5e38f28ff03a59a - SHA-1:
f8deebb228e366698f3d11aff46d64615fe09fcd - MD5:
8a8a062db1b3b21e552ed4d427ef115c - ssdeep:
1536:iGFJY/Er2HaRW/cZaAP7j/tR3aZplkEGWLjOdrh7:bFJY8r26RW/0aAP7j/tRKvaCjOd1 - TLSH:
T18436AFF3019BDDCCBBCF9B036AAB1079654ADB4871329A608498773CC5BC6BC6E10951 - Submitted as: normal_5f9a61a466a68.pdf
- File type: pdf · Size: 64764 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=adobe+illustrator+cc+2019+crack+reddit+windows, https://cdn.shopify.com/s/files/1/0496/1861/6473/files/basic_electrical_symbols_and_its_functions.pdf, https://kafaziwe.weebly.com/uploads/1/3/1/0/131070109/zomileselonojuzo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=adobe+illustrator+cc+2019+crack+reddit+windows
- https://s3.amazonaws.com/remufuzu/vamikazojemereribu.pdf
- https://cdn.shopify.com/s/files/1/0496/1861/6473/files/basic_electrical_symbols_and_its_functions.pdf
- https://kafaziwe.weebly.com/uploads/1/3/1/0/131070109/zomileselonojuzo.pdf
- https://cdn.shopify.com/s/files/1/0485/2341/1611/files/35910039850.pdf
- https://cdn.shopify.com/s/files/1/0500/4155/3046/files/86693872319.pdf
- https://foxagizak.weebly.com/uploads/1/3/4/3/134332010/5153596.pdf
- https://xujaxivef.weebly.com/uploads/1/3/1/4/131438557/292e5a3c.pdf
- https://cdn.shopify.com/s/files/1/0497/3677/7877/files/3506948535.pdf
- https://cdn.shopify.com/s/files/1/0501/6132/0097/files/photo_video_maker_with_song_download_apk.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f9149fde3daa.pdf
- https://s3.amazonaws.com/pazifetanegapu/duzin.pdf
- https://cdn.shopify.com/s/files/1/0437/7768/7706/files/schluter-shower_system_installation_handbook.pdf
- https://pexazunawilaga.weebly.com/uploads/1/3/4/2/134265520/silew.pdf
- https://dikanutedageke.weebly.com/uploads/1/3/4/4/134457663/f1ccdfd134bb.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/bumezaresokibi.pdf
- https://wubabenababi.weebly.com/uploads/1/3/4/4/134432193/zadat.pdf
- https://cdn.shopify.com/s/files/1/0432/2813/5592/files/soccer_training_books.pdf
- https://cdn-cms.f-static.net/uploads/4379742/normal_5f90ac193a849.pdf
- https://s3.amazonaws.com/tapexiw/bauhaus_movement.pdf
- https://gujibimusexuwub.weebly.com/uploads/1/3/4/0/134042380/701794.pdf
- https://cdn.shopify.com/s/files/1/0480/2389/6223/files/best_buy_rogers.pdf
- https://cdn-cms.f-static.net/uploads/4404976/normal_5f95905ea3c6e.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.me
- s3.amazonaws.com
- cdn.shopify.com
- kafaziwe.weebly.com
- foxagizak.weebly.com
- xujaxivef.weebly.com
- cdn-cms.f-static.net
- pexazunawilaga.weebly.com
- dikanutedageke.weebly.com
- pigogokeda.weebly.com
- wubabenababi.weebly.com
- gujibimusexuwub.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report