SUSPICIOUS — normal_5f985b57c2d55.pdf
SUSPICIOUS — normal_5f985b57c2d55.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b3da77eddce8b2d2d677529eee96cc56362fc325ff4421279f33757a639fc545 - SHA-1:
f8909c61d1f81c77357dfb3be5ef89a7d6792fe8 - MD5:
7ba3f19805b6bf5e8eca81e72ef8d8f2 - ssdeep:
768:XgGzpDlpz+MqX6iy2x4Pe2nOz49VcVQ3PXdXifzmQzAJZ3bicCeWI0J:wGFxpm4WZsSQ3P9ifzmQkf8I0J - TLSH:
T147318DF300ABEC8C3A8B6F47A9A715996589D74D7126D6A044CC7B3CC07C9ED6F00961 - Submitted as: normal_5f985b57c2d55.pdf
- File type: pdf · Size: 41569 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=night+train+wine+t-shirt, https://uploads.strikinglycdn.com/files/74127fb2-d647-4138-a0b1-c12b31f9ff6a/nufimujekijunewiwutage.pdf, https://uploads.strikinglycdn.com/files/96e8c18f-c552-4030-a29c-52230a7ddc48/kanoletumake.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=night+train+wine+t-shirt
- https://s3.amazonaws.com/tetazino/72144330142.pdf
- https://s3.amazonaws.com/sulasatevirexo/types_of_biscuits.pdf
- https://s3.amazonaws.com/susopuzupure/anglican_church_of_southern_africa_lectionary_2018.pdf
- https://uploads.strikinglycdn.com/files/74127fb2-d647-4138-a0b1-c12b31f9ff6a/nufimujekijunewiwutage.pdf
- https://uploads.strikinglycdn.com/files/96e8c18f-c552-4030-a29c-52230a7ddc48/kanoletumake.pdf
- https://uploads.strikinglycdn.com/files/51f723c7-498d-49a7-a8a5-bcd30178535b/comcast_smc_business_gateway_manual.pdf
- https://uploads.strikinglycdn.com/files/0dcb0c80-ab63-4346-a435-bdbeeeeaa865/buzomedusomotuxogebiw.pdf
- https://uploads.strikinglycdn.com/files/a545848d-c3ed-4b64-98cc-b849fba41d30/39382980955.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f86f6d2be887.pdf
- https://cdn-cms.f-static.net/uploads/4382406/normal_5f8f04dfdc0c7.pdf
- https://cdn-cms.f-static.net/uploads/4377095/normal_5f8ce5ccbe265.pdf
- https://cdn-cms.f-static.net/uploads/4379053/normal_5f8b58deddf23.pdf
- https://cdn-cms.f-static.net/uploads/4372355/normal_5f8ea977260bf.pdf
- https://cdn-cms.f-static.net/uploads/4370076/normal_5f93aaa3df9d7.pdf
- https://uploads.strikinglycdn.com/files/b1bec021-22d0-43ee-9c5a-10044157e308/2636690414.pdf
- https://uploads.strikinglycdn.com/files/796ff5ba-337f-435b-be3f-851bd1d68caf/rufopibexolorukuwatof.pdf
- https://uploads.strikinglycdn.com/files/1bdbd344-eb3b-49d6-b6e6-4ce69e9d6c35/fedubi.pdf
- https://uploads.strikinglycdn.com/files/0901081c-e023-4e35-94f4-5b7aa6ffa4f0/fowuvameja.pdf
- https://uploads.strikinglycdn.com/files/842d68c5-f023-43f2-9256-1849e804a413/wefetogisixiwobosi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ttraff.me
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report