SUSPICIOUS — normal_5f94148607514.pdf
SUSPICIOUS — normal_5f94148607514.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
936a8cb151baaf9723762d283b24688e6615881ddea583333e594ea1d713b438 - SHA-1:
90cb26f47670185f915692c7a997173e37db656c - MD5:
b44445c65c05b049710299cb3ab2f546 - ssdeep:
768:ougGzpDKwJSxP0ZPpvOHSSkQc2idjLwdg9vYsR/RjWbWuOyi2+X83elWoQZgfqSc:+GFmwJZ+tYAu//MEWFYqk4 - TLSH:
T1B9328EF35097ED8CBA8BAB03AEAA1199508AE74D61369750449C673CC4FC6FD3E00E51 - Submitted as: normal_5f94148607514.pdf
- File type: pdf · Size: 44425 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=how+to+disable+adblock+opera+android, https://cdn.shopify.com/s/files/1/0498/2626/7291/files/fapavilagegujikep.pdf, https://cdn.shopify.com/s/files/1/0497/8786/3201/files/kid_friendly_poetry_rubric.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=how+to+disable+adblock+opera+android
- https://cdn.shopify.com/s/files/1/0498/2626/7291/files/fapavilagegujikep.pdf
- https://cdn.shopify.com/s/files/1/0497/8786/3201/files/kid_friendly_poetry_rubric.pdf
- https://cdn.shopify.com/s/files/1/0484/0567/6192/files/husky_screwdriver_set.pdf
- https://cdn.shopify.com/s/files/1/0496/2127/0684/files/netgear_nighthawk_ac2300_r7000p_manual.pdf
- https://cdn.shopify.com/s/files/1/0488/0649/4373/files/documentum_jobs_and_methods.pdf
- https://cdn.shopify.com/s/files/1/0497/5227/7155/files/prevailing_wage_indiana.pdf
- https://woliwejimagevin.weebly.com/uploads/1/3/4/3/134319070/2031506.pdf
- https://visajemilami.weebly.com/uploads/1/3/4/2/134265887/1913235.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/7506805.pdf
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/kazotinadi.pdf
- https://cdn-cms.f-static.net/uploads/4368249/normal_5f8ea3cf73d43.pdf
- https://cdn-cms.f-static.net/uploads/4388183/normal_5f8e1de533617.pdf
- https://cdn-cms.f-static.net/uploads/4378628/normal_5f930ae7d0b01.pdf
- https://cdn.shopify.com/s/files/1/0434/4853/3144/files/98475643001.pdf
- https://cdn.shopify.com/s/files/1/0505/4952/2605/files/wapking_mp3_songs_new_bollywood.pdf
- https://cdn.shopify.com/s/files/1/0501/9025/4253/files/how_to_use_compass_in_minecraft_ps3.pdf
- https://cdn.shopify.com/s/files/1/0479/2277/4180/files/poco_launcher_apk_beta.pdf
- https://cdn-cms.f-static.net/uploads/4408851/normal_5f927d99558da.pdf
- https://cdn-cms.f-static.net/uploads/4367905/normal_5f93b55e1d951.pdf
- https://cdn-cms.f-static.net/uploads/4366666/normal_5f8788514d554.pdf
- https://cdn-cms.f-static.net/uploads/4366027/normal_5f8ba83437413.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.me
- cdn.shopify.com
- woliwejimagevin.weebly.com
- visajemilami.weebly.com
- papunagaku.weebly.com
- besiwalufeg.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report