SUSPICIOUS — normal_5f9ec8c394579.pdf
SUSPICIOUS — normal_5f9ec8c394579.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
aa4809c8ed2912893e93daf2d0bda07a9635fdab9fb07ccca8c9186645a1be9a - SHA-1:
e99953dfe55a786ab42480feb1eb7b7542d31bdb - MD5:
a9d5334be69d2f4f2c2b14b45085dfb2 - ssdeep:
1536:yGFexd0npdso0IpS6jiQP9CwCDENK7a+Qx0e:rFeMso0IpViQPkwK7pQH - TLSH:
T15934BFF3A167DD8CAA86EB1379AB1859604DCB4C6132CA6154C87B2CC8BC6BD7D40D60 - Submitted as: normal_5f9ec8c394579.pdf
- File type: pdf · Size: 53865 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=d+d+stormwrack+pdf, https://cdn.shopify.com/s/files/1/0431/6112/5013/files/88158438906.pdf, https://cdn.shopify.com/s/files/1/0438/4522/2550/files/nursing_leadership_and_management_patricia_kelly.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=d+d+stormwrack+pdf
- https://cdn.shopify.com/s/files/1/0431/6112/5013/files/88158438906.pdf
- https://cdn.shopify.com/s/files/1/0438/4522/2550/files/nursing_leadership_and_management_patricia_kelly.pdf
- https://cdn-cms.f-static.net/uploads/4393901/normal_5f960770c9f88.pdf
- https://cdn-cms.f-static.net/uploads/4372719/normal_5f9269fdc4b0c.pdf
- https://cdn.shopify.com/s/files/1/0500/3519/6067/files/citizen_grand_classic.pdf
- https://cdn.shopify.com/s/files/1/0494/2230/3399/files/bewefadumexarijufe.pdf
- https://cdn.shopify.com/s/files/1/0502/0352/5299/files/25083810804.pdf
- https://cdn.shopify.com/s/files/1/0432/7112/7208/files/56648523086.pdf
- https://cdn.shopify.com/s/files/1/0463/3070/8129/files/ender_in_exile_epub.pdf
- https://cdn.shopify.com/s/files/1/0435/1721/4874/files/cds_ota_syllabus_2020.pdf
- https://cdn.shopify.com/s/files/1/0500/6593/2437/files/76745732931.pdf
- https://cdn-cms.f-static.net/uploads/4405443/normal_5f9370720598d.pdf
- https://cdn.shopify.com/s/files/1/0492/7107/9068/files/nice_guidelines_gestational_diabetes_levels.pdf
- https://cdn-cms.f-static.net/uploads/4389586/normal_5f93881a64bbe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report