SUSPICIOUS — normal_5f8b2f5968944.pdf
SUSPICIOUS — normal_5f8b2f5968944.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
a8a1954f118a7fddb0980b726563ca64d3ecde4a9974beae109ef51aae7d6d86 - SHA-1:
df591eddbe4f7afe1a4daff68fb22e5f579b2dd9 - MD5:
65f1bc8cbd98dd99711414f5a6347413 - ssdeep:
768:8gGzpD/p8nwnaYB2DYVqGK4kmvzbJTnRioEm/Hh6ESy7fopKJXEIgfbMPz:ZGFzpSnt43vzF7RioEmfhh7OKJXYfbML - TLSH:
T14E329EF304ABEC8DBA87A3435DA31456655AD38E623BA37015E8372CD47C1BD7E00961 - Submitted as: normal_5f8b2f5968944.pdf
- File type: pdf · Size: 44871 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.club/123?keyword=ragnarok+m+thief+lvl+up+guide, https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tadib-pepalitegugoj.pdf, https://towetebofipu.weebly.com/uploads/1/3/1/4/131437669/wubetigaxolak_dipasotesowuvu_fiwaparaveli_zexapeteguje.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=ragnarok+m+thief+lvl+up+guide
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tadib-pepalitegugoj.pdf
- https://towetebofipu.weebly.com/uploads/1/3/1/4/131437669/wubetigaxolak_dipasotesowuvu_fiwaparaveli_zexapeteguje.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/sidobojugonuxexoz.pdf
- https://cdn-cms.f-static.net/uploads/4365591/normal_5f8740b8a51d1.pdf
- https://uploads.strikinglycdn.com/files/572d4234-306c-4d51-8b46-5493cb7b0202/67725391904.pdf
- https://uploads.strikinglycdn.com/files/8e28a401-e59b-4a2e-a48b-c018dd35c5d6/jofonafufo.pdf
- https://uploads.strikinglycdn.com/files/b03693cf-5479-441a-bf21-f33c03583a4c/wiz_khalifa_rolling_papers_free_download_zip.pdf
- https://uploads.strikinglycdn.com/files/552f0f9e-8141-4051-becd-d757600e6ea0/3839665737.pdf
- https://uploads.strikinglycdn.com/files/1dba6756-49c7-4ab0-8673-98a0792c7650/perfect_dark_n64_cheats.pdf
- https://tumixivig.weebly.com/uploads/1/3/1/6/131636813/soges-zixedunixiw-xedifuxewepube.pdf
- https://lejigatoni.weebly.com/uploads/1/3/1/8/131871980/2945570.pdf
- https://cdn.shopify.com/s/files/1/0467/5387/4083/files/diwima.pdf
- https://cdn.shopify.com/s/files/1/0437/1087/3750/files/51954439878.pdf
- https://cdn.shopify.com/s/files/1/0430/2451/5229/files/ecology_final_exam_review_answers.pdf
- https://cdn.shopify.com/s/files/1/0481/3884/6371/files/batman_mystery_of_the_batwoman_dvd.pdf
- https://cdn.shopify.com/s/files/1/0481/6148/9049/files/20033549800.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.club
- genigudepa.weebly.com
- towetebofipu.weebly.com
- dutitujazekap.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- tumixivig.weebly.com
- lejigatoni.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report