SUSPICIOUS — normal_5f8d55f7b0884.pdf
SUSPICIOUS — normal_5f8d55f7b0884.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
cb39c2a9a0610c97f019513242182657b0be451c4b8ad1975572ba82b15e026e - SHA-1:
72c5cbf8dd447b205feed5c3fa7449b9154b0b34 - MD5:
8d9095c72f8de0458fd0020896bfd963 - ssdeep:
768:QgGzpDHpA+jN3A+2BvuPHfbYJhbxKoAsRH8Vvdo:9GFTpvP/bYJh15ZRcVvdo - TLSH:
T150308EF30097ED4C7A8FAB07ADBB115D6549C38D603AE660859C7A2CD07CABD7E00961 - Submitted as: normal_5f8d55f7b0884.pdf
- File type: pdf · Size: 35755 bytes
- Verdict: suspicious (35/100)
Detections (2 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ttraff.me/123?keyword=sunbeam+steam+master+iron+instructions, https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rezareludufiven-voxodopi.pdf, https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/7148620.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.me/123?keyword=sunbeam+steam+master+iron+instructions
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rezareludufiven-voxodopi.pdf
- https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/7148620.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/jogowezokuvaxu.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/zebapesuluboxaj.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/a064651c.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/8c3f11ed.pdf
- https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/sojusa.pdf
- https://uploads.strikinglycdn.com/files/c488d043-7dc8-4369-8a7e-d1095ef49e54/naleveruzinexanazivakowif.pdf
- https://uploads.strikinglycdn.com/files/a904469d-0e4a-4c84-a533-a35f823141f6/nolimepa.pdf
- https://uploads.strikinglycdn.com/files/d7ec24f5-42c9-4d7b-81d4-97e3c08412da/pulebuposebamugeveratuz.pdf
- https://uploads.strikinglycdn.com/files/264100ac-5c60-47d0-9d6d-df31146fde69/busozewub.pdf
- https://uploads.strikinglycdn.com/files/fd1b6626-5ab8-4905-9b76-e929c3ad2e6c/10047996270.pdf
- https://uploads.strikinglycdn.com/files/68aa2bb4-56ec-43cd-8bb2-c09000b14c94/39699469085.pdf
- https://cdn.shopify.com/s/files/1/0499/0867/8814/files/ranezubof.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/pacman_download_for_android.pdf
- https://cdn.shopify.com/s/files/1/0432/0637/7633/files/text_free_apk_iphone.pdf
- https://cdn.shopify.com/s/files/1/0495/5255/6184/files/milap.pdf
- https://cdn.shopify.com/s/files/1/0433/6828/4319/files/something_in_the_water_music_festival_2019.pdf
- https://uploads.strikinglycdn.com/files/72c888c0-9a7a-451b-b98a-dfb8e1168f50/gasanenutowobamejixupo.pdf
- https://uploads.strikinglycdn.com/files/b7b6088e-d807-4df5-abc2-7aefd58dbf6d/vonitezipavavo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ttraff.me
- vuxozajuje.weebly.com
- nukevokisoget.weebly.com
- zoxuzuxebexot.weebly.com
- xojerajap.weebly.com
- ditiwudo.weebly.com
- jatorogerujew.weebly.com
- boguvetasitob.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report