SUSPICIOUS — normal_5f8ab94257ed7.pdf
SUSPICIOUS — normal_5f8ab94257ed7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
8dc981a668ca8febd938acde7a13b9d6c82517d65396d34e811433037177bfed - SHA-1:
4c097d56cf9ef6aa1f4ad6bff5bf73737580e877 - MD5:
e9077c14a883a2aa75b86e9bf6cd0255 - ssdeep:
768:TgGzpDDeo5BZbRBGRXtJpuX8ghkcPSVU+KxGZeavPWIQHL02Flr1n42hS1bf4m5l:sGFfehLpW8gacH03qrBDkxwmgRm13 - TLSH:
T12D339EF750E3ED8C3ACB9B039DA7119A954EE7881232D7A004887B2CD5BC6BD7E11650 - Submitted as: normal_5f8ab94257ed7.pdf
- File type: pdf · Size: 51025 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.club/123?keyword=predicting+products+of+combustion+reactions+worksheet, https://uploads.strikinglycdn.com/files/be4b96b4-5fec-4830-91b9-400d4b097cb5/mavisat.pdf, https://uploads.strikinglycdn.com/files/26a902ba-4eca-4348-a882-e78c3892ff84/69618838426.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.club/123?keyword=predicting+products+of+combustion+reactions+worksheet
- https://uploads.strikinglycdn.com/files/be4b96b4-5fec-4830-91b9-400d4b097cb5/mavisat.pdf
- https://uploads.strikinglycdn.com/files/26a902ba-4eca-4348-a882-e78c3892ff84/69618838426.pdf
- https://uploads.strikinglycdn.com/files/6580f3bf-71e2-4db7-ac97-344ee757e69a/lamepewerariledokipo.pdf
- https://uploads.strikinglycdn.com/files/2680e32b-4f7c-45af-b1b6-48a3ecd9c2ae/tonipajiror.pdf
- https://uploads.strikinglycdn.com/files/725ce0f4-6343-44a6-bdf1-984bc55c538b/depomedegilidurakarixa.pdf
- https://uploads.strikinglycdn.com/files/9190e899-be72-406e-acab-c075febcc222/ripejobunovuvadeselixemab.pdf
- https://uploads.strikinglycdn.com/files/2e1694d6-cb54-44dd-94f3-87a401b82d84/53429754136.pdf
- https://uploads.strikinglycdn.com/files/9bbe1e48-078a-4202-ad98-10eda6ac82c9/51209268540.pdf
- https://cdn-cms.f-static.net/uploads/4369926/normal_5f8940643ebba.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f8775e4423a7.pdf
- https://cdn-cms.f-static.net/uploads/4373517/normal_5f88d360c55e0.pdf
- https://cdn-cms.f-static.net/uploads/4367905/normal_5f87b6fad41f8.pdf
- https://uploads.strikinglycdn.com/files/a2289532-33fe-4b83-bf49-51f6d488642b/36155249534.pdf
- https://uploads.strikinglycdn.com/files/77c23d03-5b4f-4585-9b11-ff7a21a29cbf/66041641625.pdf
- https://uploads.strikinglycdn.com/files/f9a2a715-3a94-4944-98bc-e6d5a55f2b6b/79515771864.pdf
- https://uploads.strikinglycdn.com/files/dc5f3d42-66de-4a99-a19b-12fadc5e0c21/fakobemuluzodapen.pdf
- https://uploads.strikinglycdn.com/files/1c46162c-a1eb-4761-8e2a-2159829c5cd7/71262511202.pdf
- https://cdn.shopify.com/s/files/1/0502/3540/8576/files/root_android_6.0_apk_sin_pc.pdf
- https://cdn.shopify.com/s/files/1/0485/9510/8000/files/star_ocean_integrity_and_faithlessness_strategy_guide_download.pdf
- https://cdn.shopify.com/s/files/1/0435/3972/6487/files/languidecer_sinonimo_y_antonimos.pdf
- https://cdn.shopify.com/s/files/1/0428/4655/2227/files/lawn_mower_repair_shops_nearby.pdf
- https://cdn.shopify.com/s/files/1/0486/4475/1528/files/vegeta_action_figure_sh_figuarts.pdf
- https://cdn.shopify.com/s/files/1/0268/8247/4181/files/duxubul.pdf
- https://cdn.shopify.com/s/files/1/0486/3066/1278/files/english_for_writing_research_papers_second_edition.pdf
Embedded domains
- ttraff.club
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report