SUSPICIOUS — normal_5f8f863eb0238.pdf
SUSPICIOUS — normal_5f8f863eb0238.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
96ad051f85dd964a2469d6ee6a0a55ac4a17b26553f1e31202c4cb53fa5d5b23 - SHA-1:
40108602cb89480d6e1155c427c04a3688cf88e7 - MD5:
9a381e57ebdaba39d03cf8ad9e505354 - ssdeep:
768:GgGzpDLeF0qI3Scvae6ZbRVt4upcgVBQoApkr+ycuCIlnbu5qwg1hcciEydJQPLc:TGFfeqqNYaeKbu53IcciEwkR/k+gpznH - TLSH:
T1BF338EF35097DD4C7A876B03AEA61168618AC7497136EFA0048C776CD47C6FE7E10A60 - Submitted as: normal_5f8f863eb0238.pdf
- File type: pdf · Size: 49021 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.club/123?keyword=amazing+spider+man+apk+data+rexdl, https://uploads.strikinglycdn.com/files/f7fdd809-e634-4538-be6e-4afd5e1a6a3e/zokiwadu.pdf, https://uploads.strikinglycdn.com/files/0630f162-dc7d-4e8c-bf5d-3aef2f938400/bozoboli.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=amazing+spider+man+apk+data+rexdl
- https://uploads.strikinglycdn.com/files/f7fdd809-e634-4538-be6e-4afd5e1a6a3e/zokiwadu.pdf
- https://uploads.strikinglycdn.com/files/0630f162-dc7d-4e8c-bf5d-3aef2f938400/bozoboli.pdf
- https://uploads.strikinglycdn.com/files/04f9f763-11e8-4a06-947d-62bfab8662be/97286265514.pdf
- https://cdn.shopify.com/s/files/1/0500/4594/3971/files/xeriwuzu.pdf
- https://cdn.shopify.com/s/files/1/0494/7217/6295/files/50605346671.pdf
- https://cdn.shopify.com/s/files/1/0435/9503/8888/files/91759757652.pdf
- https://cdn.shopify.com/s/files/1/0496/6753/9093/files/kowerapulavu.pdf
- https://cdn.shopify.com/s/files/1/0497/3084/6881/files/raxapek.pdf
- https://cdn.shopify.com/s/files/1/0268/7457/7086/files/xobidezunizixixux.pdf
- https://cdn-cms.f-static.net/uploads/4390052/normal_5f8f7ed6a3c58.pdf
- https://cdn-cms.f-static.net/uploads/4367940/normal_5f8b57bbb9e71.pdf
- https://cdn-cms.f-static.net/uploads/4368989/normal_5f8d51d09cccc.pdf
- https://cdn-cms.f-static.net/uploads/4367277/normal_5f8b2fc0247e7.pdf
- https://cdn-cms.f-static.net/uploads/4382201/normal_5f8ebfa753692.pdf
- https://cdn-cms.f-static.net/uploads/4371025/normal_5f8a03e7caa9f.pdf
- https://cdn-cms.f-static.net/uploads/4368481/normal_5f87bb098bdd9.pdf
- https://cdn-cms.f-static.net/uploads/4378386/normal_5f8c9a866490b.pdf
- https://cdn-cms.f-static.net/uploads/4366662/normal_5f8f2a7691623.pdf
- https://cdn-cms.f-static.net/uploads/4368751/normal_5f88d0df8604b.pdf
- https://cdn-cms.f-static.net/uploads/4366316/normal_5f881cad57f8a.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f8c46a510327.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.club
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report