SUSPICIOUS — normal_5f8d0aed0fa12.pdf
SUSPICIOUS — normal_5f8d0aed0fa12.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
acab5024728ae79b4aa4cc2640bc6a6fb1f228e761fdeab56d931cc3bdfe3f2e - SHA-1:
6c85e7d4cd86b322530aca386c3521ea0a52d7a5 - MD5:
1210631d1daf0a2db7dda7b546fb29e9 - ssdeep:
768:8gGzpDoeaneXo26P06LSlJF2WWqwrlU9I/kit6sxy8yKa7EuITbyb0wKVK1aWw9C:ZGFEeC+j0jbQ0HVjWwRTkWh69ZP3Sdm - TLSH:
T175316CF35457ED8C3A839B13BDEB15592489C74D6237EB9109886B2CD5BCA3DBE00920 - Submitted as: normal_5f8d0aed0fa12.pdf
- File type: pdf · Size: 39323 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=solving+proportions+using+cross+products+worksheet, https://cdn.shopify.com/s/files/1/0434/7287/9782/files/vakufuxapifo.pdf, https://cdn.shopify.com/s/files/1/0438/4060/2269/files/54393780549.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=solving+proportions+using+cross+products+worksheet
- https://cdn.shopify.com/s/files/1/0434/7287/9782/files/vakufuxapifo.pdf
- https://cdn.shopify.com/s/files/1/0438/4060/2269/files/54393780549.pdf
- https://cdn.shopify.com/s/files/1/0492/1881/4118/files/47847871508.pdf
- https://cdn.shopify.com/s/files/1/0504/3968/4256/files/physical_sciences_grade_12_examination_guidelines_2020.pdf
- https://cdn.shopify.com/s/files/1/0484/7478/3906/files/not_getting_gmail_notifications_on_galaxy_s10.pdf
- https://cdn.shopify.com/s/files/1/0439/0263/2104/files/28296687793.pdf
- https://cdn.shopify.com/s/files/1/0495/9584/2709/files/damatabesowezawagatad.pdf
- https://cdn.shopify.com/s/files/1/0499/6110/7624/files/install_android_auto_on_2020_mazda_6.pdf
- https://cdn-cms.f-static.net/uploads/4369166/normal_5f87c8c4dd152.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f893bec60378.pdf
- https://cdn.shopify.com/s/files/1/0439/0020/7272/files/believers_bible_commentary_english.pdf
- https://cdn.shopify.com/s/files/1/0497/3897/3345/files/lomajosefejowuvirirolu.pdf
- https://cdn.shopify.com/s/files/1/0482/1634/2682/files/lumesimuto.pdf
- https://cdn.shopify.com/s/files/1/0485/1181/1739/files/39287104723.pdf
- https://cdn.shopify.com/s/files/1/0495/6150/1848/files/the_outsiders_chapter_5_answers.pdf
- https://cdn.shopify.com/s/files/1/0438/2703/6322/files/ginakemamu.pdf
- https://cdn.shopify.com/s/files/1/0434/2536/6165/files/weather_effects_apps_for_android.pdf
- https://cdn.shopify.com/s/files/1/0478/8446/8390/files/nioh_two_in_the_shadows_coop.pdf
- https://cdn.shopify.com/s/files/1/0504/3467/0790/files/alexandria_ocasio_cortez_green_new_deal.pdf
- https://cdn.shopify.com/s/files/1/0431/8140/8416/files/computer_shooting_games_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0268/8558/7141/files/pemazalodojitawiba.pdf
- https://cdn.shopify.com/s/files/1/0502/9324/4069/files/gukekikulaxikanu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.link
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report