SUSPICIOUS — normal_5f8b2397c31f4.pdf
SUSPICIOUS — normal_5f8b2397c31f4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
b8669ef01734a25f3929d57033077a5a8b1fa0f92ff0a71f6b600e2fab6f2e9c - SHA-1:
af4842daff19aa7d721ccab805fc1d1f1a65da45 - MD5:
7ff740d8f46473911a63f6e771bec963 - ssdeep:
768:VgGzpDvlpzt4ss4Lg6IUpA0UnfJVj4Jn/2LgjoDqiRJZmBdx4tGU7to3I+WG33rc:GGFJpJ/NJijMxCFj+W1JAE - TLSH:
T1EF337EF750EBDD4D7B869B03ADA71155608EC78862279B90418CBB2CC5BC5ADBE20860 - Submitted as: normal_5f8b2397c31f4.pdf
- File type: pdf · Size: 48621 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=pokemon+masters+32+bit+version+apk, https://cdn-cms.f-static.net/uploads/4375357/normal_5f8979f9c12e7.pdf, https://cdn-cms.f-static.net/uploads/4366029/normal_5f872ad168629.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.cc/123?keyword=pokemon+masters+32+bit+version+apk
- https://cdn-cms.f-static.net/uploads/4375357/normal_5f8979f9c12e7.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f872ad168629.pdf
- https://cdn-cms.f-static.net/uploads/4369936/normal_5f8813d586985.pdf
- https://cdn-cms.f-static.net/uploads/4375070/normal_5f8a56a164531.pdf
- https://cdn-cms.f-static.net/uploads/4365601/normal_5f8afecc1c796.pdf
- https://uploads.strikinglycdn.com/files/60e1840b-cb88-4a87-be62-59398dd778f1/8467693039.pdf
- https://uploads.strikinglycdn.com/files/65fe00a3-9790-4e51-a0d7-1553f5d81e48/95522475896.pdf
- https://uploads.strikinglycdn.com/files/d46b22c0-7955-4252-9559-1bbb72e8324d/soberexefulibopadox.pdf
- https://uploads.strikinglycdn.com/files/c61e2adc-39c6-480e-befd-d43887e03abb/32859199786.pdf
- https://uploads.strikinglycdn.com/files/0fbbde4a-29a3-4862-b104-43d72927b5f8/jazuzekasexokototezu.pdf
- https://uploads.strikinglycdn.com/files/12383322-485c-43ee-bd76-a9e1bbf35c37/41395875084.pdf
- https://uploads.strikinglycdn.com/files/b90b8626-9bc7-42d9-ae89-208891f8d388/mazopina.pdf
- https://uploads.strikinglycdn.com/files/969cda04-cb0a-40ca-aa88-ccd04689a4b1/62571161434.pdf
- https://uploads.strikinglycdn.com/files/95f6eff9-d812-46c9-bb05-3a6acd79919a/geridugasukisewizupu.pdf
- https://cdn.shopify.com/s/files/1/0501/4093/8410/files/19682428300.pdf
- https://cdn.shopify.com/s/files/1/0503/4967/0560/files/kadutusemogasemime.pdf
- https://cdn.shopify.com/s/files/1/0495/5229/4055/files/womens_electric_razor_walgreens.pdf
- https://cdn.shopify.com/s/files/1/0431/5847/0816/files/machinarium_apk_android_download.pdf
- https://cdn.shopify.com/s/files/1/0439/3802/1531/files/35846957947.pdf
- https://cdn.shopify.com/s/files/1/0486/2627/0366/files/95548031235.pdf
- https://cdn.shopify.com/s/files/1/0266/8068/8836/files/8th_grade_science_eog_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0439/1731/2152/files/29186642616.pdf
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f86f597a2119.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f871073ca33f.pdf
Embedded domains
- ttraff.cc
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report