SUSPICIOUS — normal_5f8d831880174.pdf
SUSPICIOUS — normal_5f8d831880174.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
85095e3db4535ce66eec5792efc618017fd01d7bc874469ec77cefde142e96da - SHA-1:
15511af428162db6070a912a61a8be60c3f08b17 - MD5:
1ecd6bbe743b432bfc32b6eba5b422e9 - ssdeep:
768:/LgGzpDIpafcgOZQ63OMAHXC52MO1GeLRhCTvJG0nXZTXhVMnMYuYd99wM205C8C:MGFsp9e60F1GeLyV0M4d9+M2ybef/ygl - TLSH:
T167328DF350A7ED4D7E8BAF535EBB1165644AC688B0379BA010C83B2CC4B86FD2E50561 - Submitted as: normal_5f8d831880174.pdf
- File type: pdf · Size: 45911 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=towelroot+4.4.2+apk+download, https://cdn-cms.f-static.net/uploads/4366956/normal_5f8757abd7f68.pdf, https://cdn-cms.f-static.net/uploads/4380539/normal_5f8d476189469.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=towelroot+4.4.2+apk+download
- https://cdn-cms.f-static.net/uploads/4366956/normal_5f8757abd7f68.pdf
- https://cdn-cms.f-static.net/uploads/4380539/normal_5f8d476189469.pdf
- https://cdn-cms.f-static.net/uploads/4374851/normal_5f891aa476529.pdf
- https://cdn-cms.f-static.net/uploads/4386361/normal_5f8ccc957c6ae.pdf
- https://cdn-cms.f-static.net/uploads/4383925/normal_5f8bee289f478.pdf
- https://cdn-cms.f-static.net/uploads/4371505/normal_5f8b950be1fc4.pdf
- https://cdn-cms.f-static.net/uploads/4369663/normal_5f87f8c48aaed.pdf
- https://cdn-cms.f-static.net/uploads/4367617/normal_5f8d15045fa21.pdf
- https://cdn-cms.f-static.net/uploads/4367278/normal_5f87f30c0a701.pdf
- https://cdn.shopify.com/s/files/1/0497/4415/0689/files/lowrance_hds_5_for_sale.pdf
- https://cdn.shopify.com/s/files/1/0436/0224/7838/files/kutefojexiz.pdf
- https://cdn.shopify.com/s/files/1/0498/6080/4770/files/free_choral_warm_ups_sheet_music.pdf
- https://cdn-cms.f-static.net/uploads/4366371/normal_5f874bbc7fef6.pdf
- https://cdn-cms.f-static.net/uploads/4366358/normal_5f87df0718e1b.pdf
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f86f42f6c975.pdf
- https://uploads.strikinglycdn.com/files/35d68108-69ad-4b68-8f91-4d9074d00ac8/tegaraxofa.pdf
- https://uploads.strikinglycdn.com/files/e1891312-eceb-40b2-a71a-c7033a7cf78c/ejercicios_resueltos_teoria_de_colas.pdf
- https://uploads.strikinglycdn.com/files/4e50e6a6-3f93-463d-b121-ba1bd8163dfa/madujesesipofatolenipi.pdf
- https://uploads.strikinglycdn.com/files/9fb3208d-2722-4adb-b2fd-24d3add04b50/dalizamoxi.pdf
- https://uploads.strikinglycdn.com/files/4d4d1beb-49ee-4fcd-b001-d21a8473558e/sixugesafigixebujuwulopa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ttraff.cc
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report