SUSPICIOUS — normal_5f99097c9d964.pdf
SUSPICIOUS — normal_5f99097c9d964.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
d15a07cc4f2d10929d9e3999f87ed47d818022328c986dd3fe28e2c5034ad260 - SHA-1:
e3dbd7e4739655e7484edaba5d5d721cce663aea - MD5:
6ab2d98c0b9bca46a61455820cac9940 - ssdeep:
1536:SMGFfecUy2MntWKJg1uirazWZIr3n9ndWzK9I+40QCf:SpFfecV2MfJt+azWyJL9I+40F - TLSH:
T14C359EF3119BDD4C7AC6EF03A8AB15281049D68C2232E7E558D8772CD47CABE7E60950 - Submitted as: normal_5f99097c9d964.pdf
- File type: pdf · Size: 57843 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=bigg+boss+11+17th+december+2017+calendar, https://cdn.shopify.com/s/files/1/0500/4807/3899/files/lidanarimepefaxikolakox.pdf, https://cdn.shopify.com/s/files/1/0481/6348/7897/files/funimation_dragon_ball_z_kai.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=bigg+boss+11+17th+december+2017+calendar
- https://cdn.shopify.com/s/files/1/0500/4807/3899/files/lidanarimepefaxikolakox.pdf
- https://cdn.shopify.com/s/files/1/0481/6348/7897/files/funimation_dragon_ball_z_kai.pdf
- https://cdn.shopify.com/s/files/1/0503/2417/7093/files/pokerstars_app_android_real_money.pdf
- https://uploads.strikinglycdn.com/files/38a26d88-4f8f-4e7e-9dc5-2eada1631f0e/kinemap.pdf
- https://uploads.strikinglycdn.com/files/569c0c6e-c262-49bd-86f8-1036ee39467e/70621458348.pdf
- https://uploads.strikinglycdn.com/files/bd6a332a-5d38-4331-8a09-5ddc3ae51167/22389684237.pdf
- https://buximinolid.weebly.com/uploads/1/3/1/3/131381316/tuwofoxuzuritel.pdf
- https://bajusumuke.weebly.com/uploads/1/3/2/7/132741128/3047140.pdf
- https://vozupixog.weebly.com/uploads/1/3/4/3/134312338/ruguravumobo-zipizeviride-riger-malupimib.pdf
- https://cdn-cms.f-static.net/uploads/4381788/normal_5f8f2a122b65a.pdf
- https://cdn-cms.f-static.net/uploads/4403407/normal_5f97f46c73e1d.pdf
- https://cdn-cms.f-static.net/uploads/4381083/normal_5f98c69183344.pdf
- https://uploads.strikinglycdn.com/files/3c932170-bf33-422c-a926-01a19941bf2f/48577656458.pdf
- https://uploads.strikinglycdn.com/files/df393bed-0f00-40c7-9781-a69e8f4b64ab/lifesaver_smoke_alarm_model_1275_instructions.pdf
- https://uploads.strikinglycdn.com/files/78ae6369-0224-48e2-8418-1f06c5682fbd/gesisumikimirazevoz.pdf
- https://uploads.strikinglycdn.com/files/9d6961b6-b54f-4908-a141-aab641f2d7aa/28006248740.pdf
- https://uploads.strikinglycdn.com/files/4c199173-ed4c-4311-95ab-44d7a44ed0b5/cardiologia_pediatrica_libro.pdf
- https://cdn.shopify.com/s/files/1/0493/1957/5718/files/70544121453.pdf
- https://cdn.shopify.com/s/files/1/0498/7571/4209/files/brandywine_springs_school_supply_list.pdf
- https://cdn.shopify.com/s/files/1/0428/0621/4819/files/holden_barina_2020_manual.pdf
- https://cdn.shopify.com/s/files/1/0476/6128/5542/files/40385215289.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.cc
- cdn.shopify.com
- uploads.strikinglycdn.com
- buximinolid.weebly.com
- bajusumuke.weebly.com
- vozupixog.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report