SUSPICIOUS — normal_5f8b2d9187b16.pdf
SUSPICIOUS — normal_5f8b2d9187b16.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
c8f434bcd2274c6a7a935ec8f8d8053306792d66e04c077093d29e29443cdfb0 - SHA-1:
d7a296b573cabe0fa7ce0b4358b1d04a3b34d259 - MD5:
61eec9e196d9f350658da5801795c45a - ssdeep:
768:+gGzpDypEyXe9JWE7N7zQUIBeyu4P3MNR45BJyrbVALcCGt+IOJAzrNZhm9lytW2:7GFWpkN7zBFCHI4A3NGHeoczpD3 - TLSH:
T1AE35AFF310A7EC4C7ACB9B03A9EA166E7149D7892122EA5045C8772CC47C7FD7E50A21 - Submitted as: normal_5f8b2d9187b16.pdf
- File type: pdf · Size: 58148 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=who+visited+my+facebook+profile+apk, https://cdn.shopify.com/s/files/1/0497/3897/3345/files/tumuxalegirisakenig.pdf, https://cdn.shopify.com/s/files/1/0495/9558/0579/files/rerumavipiwukofi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=who+visited+my+facebook+profile+apk
- https://cdn.shopify.com/s/files/1/0497/3897/3345/files/tumuxalegirisakenig.pdf
- https://cdn.shopify.com/s/files/1/0495/9558/0579/files/rerumavipiwukofi.pdf
- https://cdn.shopify.com/s/files/1/0437/5796/1365/files/nursing_diagnosis_for_muscle_weakness.pdf
- https://cdn.shopify.com/s/files/1/0430/2172/9955/files/puvufukaka.pdf
- https://cdn.shopify.com/s/files/1/0485/8711/2613/files/downton_abbey_jewelry_amazon.pdf
- https://cdn-cms.f-static.net/uploads/4367300/normal_5f8a324cf400e.pdf
- https://cdn-cms.f-static.net/uploads/4370059/normal_5f8822f6c3d77.pdf
- https://cdn-cms.f-static.net/uploads/4375093/normal_5f8a3f31e41b5.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f88456c1599f.pdf
- https://cdn-cms.f-static.net/uploads/4365546/normal_5f89d7c949fc4.pdf
- https://uploads.strikinglycdn.com/files/fc67a4da-5130-4530-b915-9275aab3aa39/96658175055.pdf
- https://uploads.strikinglycdn.com/files/4ff1889d-1071-4a6d-999a-246895ab635c/25434827267.pdf
- https://uploads.strikinglycdn.com/files/0af2afe4-90fd-4669-9766-a9716d87f5b1/2641353363.pdf
- https://uploads.strikinglycdn.com/files/1b5c7ebb-695b-4ac5-b910-7fc7af8a33dc/dogizomadabow.pdf
- https://uploads.strikinglycdn.com/files/8aad1b8a-31dd-48a2-954b-d5996c72544a/jumebubutadekepekosidode.pdf
- https://cdn.shopify.com/s/files/1/0434/5584/0409/files/81753848888.pdf
- https://cdn.shopify.com/s/files/1/0496/1288/2071/files/ozymandias_summary_and_analysis.pdf
- https://cdn.shopify.com/s/files/1/0501/4061/0725/files/beaulo_sensitivity_settings_2019.pdf
- https://cdn.shopify.com/s/files/1/0484/5371/4070/files/rupi_kaur_milk_and_honey_ebook.pdf
- https://cdn-cms.f-static.net/uploads/4365655/normal_5f871f98c2a45.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f87072455f7d.pdf
- https://cdn.shopify.com/s/files/1/0486/2335/4021/files/james_fadiman_the_psychedelic_explorers_guide.pdf
- https://cdn.shopify.com/s/files/1/0496/6121/4877/files/pojuzaxututuxuwidumew.pdf
- https://cdn.shopify.com/s/files/1/0486/5431/9774/files/windows_server_administration_fundamentals_study_guide.pdf
Embedded domains
- ttraff.cc
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report