SUSPICIOUS — normal_5f8bf1622c3df.pdf
SUSPICIOUS — normal_5f8bf1622c3df.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
c1f41e9e36cfe46a5be246246f567544779f950e0b5a5d6e5a213a37e0b4af30 - SHA-1:
321d5b041a1ccca302364ba7ec154e15712dec84 - MD5:
de9565e86ca23e159559833959c2cb44 - ssdeep:
768:MRgGzpDueyubdAtC4G4bZ+HUmwyjUYURIJXIrFO/hrmEzVcqa2G0+m413N21nwB7:XGFSeyuBUYURRrFO/UEzVcqaP0013NA+ - TLSH:
T101328DF310D7DC8CBA87DB43ADBA2565648AC7486236C7A0548C7B2CC5BC6BD7E01960 - Submitted as: normal_5f8bf1622c3df.pdf
- File type: pdf · Size: 47065 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=unable+to+open+word+document+on+android, https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/lonasexevexa.pdf, https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/vonugumazagusu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.link/123?keyword=unable+to+open+word+document+on+android
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/lonasexevexa.pdf
- https://jizonuwuko.weebly.com/uploads/1/3/0/8/130814311/vonugumazagusu.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/4941059.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/pelupe.pdf
- https://gadigode.weebly.com/uploads/1/3/2/6/132680949/serenizevivowubon.pdf
- https://uploads.strikinglycdn.com/files/3a668ca0-65d3-4637-990c-30978fa10851/padebosu.pdf
- https://uploads.strikinglycdn.com/files/617cc1a8-7772-41c5-91c0-470364ad5762/57396127866.pdf
- https://cdn-cms.f-static.net/uploads/4378857/normal_5f8b3061069e4.pdf
- https://cdn-cms.f-static.net/uploads/4370525/normal_5f8acd95acf13.pdf
- https://cdn-cms.f-static.net/uploads/4378379/normal_5f8b4897a0477.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f86ffb9c63ce.pdf
- https://cdn-cms.f-static.net/uploads/4370051/normal_5f89cbad4a007.pdf
- https://uploads.strikinglycdn.com/files/e8b1eae8-01c9-40b2-a2a0-1c98f07a77c3/kovabakejeb.pdf
- https://uploads.strikinglycdn.com/files/3b414031-6bad-4e2a-8792-880dcfc40a61/8465965208.pdf
- https://uploads.strikinglycdn.com/files/7576c7a3-60de-4929-99a1-2d10e23085cd/zifujus.pdf
- https://uploads.strikinglycdn.com/files/07e4f854-7fac-4e57-a79a-396a7d139e36/24667223833.pdf
- https://uploads.strikinglycdn.com/files/a5c4b8de-03ae-436c-98c2-94b993da2d50/53491408970.pdf
- https://uploads.strikinglycdn.com/files/057e97e8-7849-4bf8-9a4b-829beeaf451b/6566163339.pdf
- https://uploads.strikinglycdn.com/files/0e7fd49c-41e2-4b06-85b4-d4ca22899487/53369860967.pdf
- https://uploads.strikinglycdn.com/files/0fb33b23-18a2-4466-89b0-01f55968eb9b/choices_pre-intermediate_wo.pdf
- https://uploads.strikinglycdn.com/files/2ff52f2e-4f55-4fef-9811-74c407b1bdaf/gagevadasubu.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f873ec15f581.pdf
- https://cdn-cms.f-static.net/uploads/4366642/normal_5f8851158753d.pdf
- https://cdn-cms.f-static.net/uploads/4379616/normal_5f8bc4dcbb544.pdf
Embedded domains
- ttraff.link
- pavowojavujide.weebly.com
- jizonuwuko.weebly.com
- jakedekokobara.weebly.com
- vilukenuxe.weebly.com
- gadigode.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report