SUSPICIOUS — normal_5f944c5a72725.pdf
SUSPICIOUS — normal_5f944c5a72725.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
bb8649fe1a9c4d7531fedf5b5386e1adea8b380c04350e34bfec652cdc527ea2 - SHA-1:
416facbde2500dfcf05f4ecb186b22a0b7a7b994 - MD5:
2e054af75defffbf32aac4ea8c5c5da6 - ssdeep:
768:lgGzpDjcv5qkDM3OjBU/mRKMX+jF5Mlx15g6RviMHj7LJiOLIXJxEEu:2GFvcxX+hA15/tiMD7FLEXJxEEu - TLSH:
T1AA306DF350A7DD8C368F9B13AEAB1699348AC6886237D7500488673CD47C9FD6F11A21 - Submitted as: normal_5f944c5a72725.pdf
- File type: pdf · Size: 38179 bytes
- Verdict: suspicious (35/100)
Detections (2 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=curtin+bentley+campus+map+pdf, https://uploads.strikinglycdn.com/files/ece5ec6a-a606-4c05-bed5-308a551b8836/36189526527.pdf, https://uploads.strikinglycdn.com/files/6f79e280-21b2-465b-a620-1e110fdb5196/93987139002.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=curtin+bentley+campus+map+pdf
- https://uploads.strikinglycdn.com/files/ece5ec6a-a606-4c05-bed5-308a551b8836/36189526527.pdf
- https://uploads.strikinglycdn.com/files/6f79e280-21b2-465b-a620-1e110fdb5196/93987139002.pdf
- https://uploads.strikinglycdn.com/files/ebfa0c5a-4ec1-49fd-be50-0bd19ce728d7/eat_like_you_give_a_fuck.pdf
- https://cdn-cms.f-static.net/uploads/4369630/normal_5f8d4f85b2ab0.pdf
- https://cdn-cms.f-static.net/uploads/4378161/normal_5f8e0cff2982b.pdf
- https://cdn-cms.f-static.net/uploads/4387232/normal_5f8f453e70a25.pdf
- https://cdn-cms.f-static.net/uploads/4384152/normal_5f8c7c60dc114.pdf
- https://cdn-cms.f-static.net/uploads/4369631/normal_5f8928ddc4f13.pdf
- https://cdn.shopify.com/s/files/1/0266/9494/2919/files/hal_leonard_classical_guitar_method.pdf
- https://cdn.shopify.com/s/files/1/0431/1433/2309/files/84565769142.pdf
- https://cdn.shopify.com/s/files/1/0501/8697/7441/files/27233359128.pdf
- https://cdn.shopify.com/s/files/1/0481/6316/0231/files/kenmore_microwave_convection_oven_instructions.pdf
- https://cdn.shopify.com/s/files/1/0484/2045/4554/files/38089791029.pdf
- https://cdn-cms.f-static.net/uploads/4407318/normal_5f93dc71351d1.pdf
- https://cdn-cms.f-static.net/uploads/4379236/normal_5f9236f9263e5.pdf
- https://xedaliwim.weebly.com/uploads/1/3/1/4/131454603/xisuvumuxefisa.pdf
- https://nipaxibovaj.weebly.com/uploads/1/3/1/3/131379211/3606590.pdf
- https://nirejabepifu.weebly.com/uploads/1/3/4/2/134266024/powipovadir.pdf
- https://zoveponezewuda.weebly.com/uploads/1/3/0/7/130738822/pawotexoxaramitase.pdf
- https://robavefozaxun.weebly.com/uploads/1/3/4/3/134379548/mevaxalenuvifapa.pdf
- https://vunixumo.weebly.com/uploads/1/3/1/4/131453253/9c4cf4665.pdf
- https://bafovulik.weebly.com/uploads/1/3/1/0/131070506/0a4d320e6.pdf
- https://mogidudurunupiz.weebly.com/uploads/1/3/2/6/132695636/katulepunusuvenag.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.me
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- xedaliwim.weebly.com
- nipaxibovaj.weebly.com
- nirejabepifu.weebly.com
- zoveponezewuda.weebly.com
- robavefozaxun.weebly.com
- vunixumo.weebly.com
- bafovulik.weebly.com
- mogidudurunupiz.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report