SUSPICIOUS — normal_5f93881a64bbe.pdf
SUSPICIOUS — normal_5f93881a64bbe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
89156d96a6401109b69586a252418a3d987e4db6ccad15061488d782294df4f4 - SHA-1:
47c840aad849959920764af707cb8eb42a788a6a - MD5:
720b762293e166b33a72ebcca88edb54 - ssdeep:
768:1ygGzpD3yhgRX6yws6vARNsVNx1vYXMFHimxs7bJfRe3JfzxBVuXsoFlWOTjSxVi:xGFTwNvVFH9wM3J/VuXsoFl3jIVf6 - TLSH:
T18932AEF740ABEC4C3E8AAB536DB700665649C38C71729A61549C363CC07C6BEBF50A61 - Submitted as: normal_5f93881a64bbe.pdf
- File type: pdf · Size: 46464 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=learn+indonesian+language+in+english+pdf, https://cdn.shopify.com/s/files/1/0429/9502/4025/files/binging_with_babish_cookbook.pdf, https://cdn.shopify.com/s/files/1/0501/5296/4266/files/audio_editing_software_free_for_android.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.cc/123?keyword=learn+indonesian+language+in+english+pdf
- https://cdn.shopify.com/s/files/1/0429/9502/4025/files/binging_with_babish_cookbook.pdf
- https://cdn.shopify.com/s/files/1/0501/5296/4266/files/audio_editing_software_free_for_android.pdf
- https://cdn.shopify.com/s/files/1/0500/3857/1168/files/best_android_media_player_library.pdf
- https://cdn.shopify.com/s/files/1/0501/1973/7544/files/skyrim_best_first_person_mod.pdf
- https://uploads.strikinglycdn.com/files/3927f05e-fc36-4e16-a8ff-67d4831f3aa7/hikayeler_anton_ehov.pdf
- https://uploads.strikinglycdn.com/files/dfb5f408-3e3b-4791-9405-0b1e3c64e039/kajuwi.pdf
- https://uploads.strikinglycdn.com/files/5782f80e-0da4-468e-ac18-a0b3caf5d507/nomizuse.pdf
- https://uploads.strikinglycdn.com/files/1356fcc7-01d6-48e2-a4bc-05ab64f1d881/52227600119.pdf
- https://uploads.strikinglycdn.com/files/d74259cf-5329-4b8e-a5e5-9fd04b9b1996/38573798444.pdf
- https://uploads.strikinglycdn.com/files/364239ce-1381-4e2b-88a4-748ce00e2688/97322939119.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/d8d72.pdf
- https://jijalasigode.weebly.com/uploads/1/3/4/3/134344414/loxixanopomut_lelusalarowobax_bewukog_kowatavetekak.pdf
- https://cdn.shopify.com/s/files/1/0432/5995/3312/files/best_music_manager_app_for_android.pdf
- https://cdn.shopify.com/s/files/1/0504/8539/5621/files/69899174565.pdf
- https://cdn.shopify.com/s/files/1/0266/8878/2506/files/pebafusazesuzik.pdf
- https://cdn.shopify.com/s/files/1/0431/4975/4519/files/lagemefijumomuwetakaka.pdf
- https://s3.amazonaws.com/zetare/igcse_chemistry_past_papers_2017.pdf
- https://s3.amazonaws.com/zurovajij/family_worksheet_for_kindergarten.pdf
- https://s3.amazonaws.com/jamokaroxoj/poboverazaboledexetej.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ttraff.cc
- cdn.shopify.com
- uploads.strikinglycdn.com
- tavumake.weebly.com
- jijalasigode.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report