SUSPICIOUS — normal_5f91f75bb3872.pdf
SUSPICIOUS — normal_5f91f75bb3872.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
9a20444ca1d9da2ceffb2460a3f9630d8bddb20f246eb2000a168b88baa684e9 - SHA-1:
da9071ed31f70336f667150498f461abb8b81ed1 - MD5:
117522010daed658e0e13c5ec4d04f47 - ssdeep:
768:ZjgGzpDBpk2VFmfUNaFF9DDjUp+zZ3qRZsUwZaINBgTiE:ZcGF1pksYUpEaRZsUwaTiE - TLSH:
T1D4319DF355D7DD8C7F8BAB03ADBA10555085D28C6127E76009C87B6CC0BC6AEAF20861 - Submitted as: normal_5f91f75bb3872.pdf
- File type: pdf · Size: 40130 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/123?keyword=christmas+math+coloring+worksheets+3rd+grade, https://cdn-cms.f-static.net/uploads/4369152/normal_5f8a448bf175b.pdf, https://cdn-cms.f-static.net/uploads/4366335/normal_5f87d84393a8c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=christmas+math+coloring+worksheets+3rd+grade
- https://cdn-cms.f-static.net/uploads/4369152/normal_5f8a448bf175b.pdf
- https://cdn-cms.f-static.net/uploads/4366335/normal_5f87d84393a8c.pdf
- https://cdn-cms.f-static.net/uploads/4367632/normal_5f88acf5ddd02.pdf
- https://s3.amazonaws.com/xanebavifamopez/55842495565.pdf
- https://s3.amazonaws.com/jifesu/alpert_valvular_heart_disease.pdf
- https://uploads.strikinglycdn.com/files/b33b57c3-73ba-4d21-92fa-47e06d8b9ac7/89671006410.pdf
- https://uploads.strikinglycdn.com/files/0ca4edaf-15f4-4004-9729-c9e6f63ba08b/15563734770.pdf
- https://uploads.strikinglycdn.com/files/a0a02f48-ba9b-4379-9722-8ccff3e14285/how_to_deflect_for_honor.pdf
- https://uploads.strikinglycdn.com/files/b6fd9536-643d-46c2-9b26-b8b6d4f5b00c/suponasodivezovexanireb.pdf
- https://uploads.strikinglycdn.com/files/46ca688a-a254-4b45-9362-627e767766f9/jirofisizodelitavelu.pdf
- https://cdn.shopify.com/s/files/1/0431/8062/1984/files/jitarubanegax.pdf
- https://cdn.shopify.com/s/files/1/0428/5962/6655/files/93447205992.pdf
- https://uploads.strikinglycdn.com/files/d5cfa6aa-5746-4033-861c-c9c1fc779d73/la_bruja_maruja_cancion_infantil_mar.pdf
- https://uploads.strikinglycdn.com/files/28f266b8-0a57-4acb-bc99-f68634161a66/vajezelum.pdf
- https://uploads.strikinglycdn.com/files/0d5a8cc6-eae7-429b-b081-64c9aa578741/52803239712.pdf
- https://uploads.strikinglycdn.com/files/851ce4bb-8bfe-4205-a3fa-fb7f8435a8f0/59290514540.pdf
- https://uploads.strikinglycdn.com/files/5858b44d-c1d0-4ea6-815f-cc982eb00d2f/15129223082.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report