SUSPICIOUS — normal_5f89cfba3139f.pdf
SUSPICIOUS — normal_5f89cfba3139f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b41f0147bf6e302090d3a2f12b75977b0828c36967605283d0e46e2792ae9b6d - SHA-1:
67098ba409968114a673eda371ec0ba0ccdc2daa - MD5:
cf8963977dd66c80fdd62a7343816696 - ssdeep:
768:5gGzpDRpYzUcrqlV6XnOgFDuKgZVOvb/QtDfa3HobBLwyPRVDeSFnziCmv99:6GFtpnz2b/Oe3WEyZNiCk9 - TLSH:
T1B3328DF310A7ED8D7E8E9F13ADEB01A8554AC7895033D36108DC322CD5B89ED6E11A61 - Submitted as: normal_5f89cfba3139f.pdf
- File type: pdf · Size: 43695 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/123?keyword=how+to+unprotect+pdf+file+for+printing, https://cdn-cms.f-static.net/uploads/4365620/normal_5f88649f8eb7d.pdf, https://cdn-cms.f-static.net/uploads/4371247/normal_5f899f5cb5462.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=how+to+unprotect+pdf+file+for+printing
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f88649f8eb7d.pdf
- https://cdn-cms.f-static.net/uploads/4371247/normal_5f899f5cb5462.pdf
- https://cdn-cms.f-static.net/uploads/4367911/normal_5f876147a59fb.pdf
- https://cdn-cms.f-static.net/uploads/4367625/normal_5f874e59e9913.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f87e6f364972.pdf
- https://cdn-cms.f-static.net/uploads/4366408/normal_5f875d5031d49.pdf
- https://uploads.strikinglycdn.com/files/5bd9d1f2-94be-4fd6-953e-44a8c5801e72/939595714.pdf
- https://uploads.strikinglycdn.com/files/3911c686-7b75-4878-bbf1-b570a33ac86d/56849512180.pdf
- https://cdn.shopify.com/s/files/1/0484/5535/2481/files/xuwifapamuburokon.pdf
- https://cdn.shopify.com/s/files/1/0502/7024/0936/files/85876760871.pdf
- https://cdn.shopify.com/s/files/1/0498/7669/7246/files/14864785725.pdf
- https://uploads.strikinglycdn.com/files/c2a8d792-25c8-4882-b88c-cd2d3939ad39/57347008275.pdf
- https://uploads.strikinglycdn.com/files/7a3cefcd-77bf-41ff-a472-abde77e485fb/12372140325.pdf
- https://uploads.strikinglycdn.com/files/c2d59239-b9e4-4c04-b0ef-1676591e258b/wakusis.pdf
- https://uploads.strikinglycdn.com/files/9a0abc7d-19dc-4453-9da4-ed1a05458cd2/18604067898.pdf
- https://uploads.strikinglycdn.com/files/47fcc4b2-9b28-41f1-9c2f-07761f0168fa/28301230822.pdf
- https://cdn.shopify.com/s/files/1/0440/7725/2760/files/the_discipline_of_market_leaders_michael_treacy.pdf
- https://cdn.shopify.com/s/files/1/0500/5718/3400/files/20591000061.pdf
- https://cdn.shopify.com/s/files/1/0499/9161/4614/files/kentucky_youth_soccer_rankings.pdf
- https://cdn.shopify.com/s/files/1/0430/8241/6281/files/best_cobalt_pickaxe_tinkers_construct.pdf
- https://cdn.shopify.com/s/files/1/0439/3009/1688/files/blackmagic_pocket_6k_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report