SUSPICIOUS — normal_5f8d9cbfc0f90.pdf
SUSPICIOUS — normal_5f8d9cbfc0f90.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e1d131dbe19786ecae83d350ebcd6bced7b54be2462e5605a0955a4ddfa6ecb5 - SHA-1:
7aecfb7580f24fb96d8ec014cc744c209474c3cb - MD5:
51b0a001c41b201f90e326a9a4842239 - ssdeep:
1536:+GFHpLBpVNIICOHhm/4crtZsdKSc0MUlD96fGWaVkp:nFHpLtNI4otwKSt952D - TLSH:
T10936CFF3559BED8C7A8B5B03A9B621A55288C3CA3136DB9054D8377DC0BC2BC7E10961 - Submitted as: normal_5f8d9cbfc0f90.pdf
- File type: pdf · Size: 69585 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=kolin+window+type+inverter+aircon+manual, https://uploads.strikinglycdn.com/files/313fae98-b423-44ee-af53-d811d917a189/5899756017.pdf, https://uploads.strikinglycdn.com/files/1446b39e-db46-432d-9f0c-5fc1816e5408/fanerila.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=kolin+window+type+inverter+aircon+manual
- https://uploads.strikinglycdn.com/files/313fae98-b423-44ee-af53-d811d917a189/5899756017.pdf
- https://uploads.strikinglycdn.com/files/1446b39e-db46-432d-9f0c-5fc1816e5408/fanerila.pdf
- https://uploads.strikinglycdn.com/files/31dff596-2c32-4cb8-a218-8f0c549cc1b2/sevepajosepawibakivelaje.pdf
- https://uploads.strikinglycdn.com/files/0f2d4dd5-546f-49bb-b54f-3a2577712b63/pamedomuletebezixu.pdf
- https://uploads.strikinglycdn.com/files/39d66f8d-f509-4fac-b21b-4cb5f4e41a84/41069165158.pdf
- https://uploads.strikinglycdn.com/files/162dc5b9-efe1-48c6-a0fb-a5b5aa92d3db/kexasilik.pdf
- https://uploads.strikinglycdn.com/files/30828947-e9a8-4f10-9d3e-aa33b9e5ecbd/wildfire_tv_series_episode_guide.pdf
- https://uploads.strikinglycdn.com/files/70cade54-e4cb-4008-aeab-48d2fd74c590/fisher_price_customer_service_replac.pdf
- https://tugajepefur.weebly.com/uploads/1/3/1/4/131453805/ebd2dd66f69ebd0.pdf
- https://xopaluwejur.weebly.com/uploads/1/3/1/8/131857284/7524844.pdf
- https://pujatimosu.weebly.com/uploads/1/3/2/6/132681823/zivatenivesek.pdf
- https://wegotutitupal.weebly.com/uploads/1/3/1/4/131453182/nowoso.pdf
- https://jurizimobijagi.weebly.com/uploads/1/3/0/8/130874317/4374342.pdf
- https://worozimovazez.weebly.com/uploads/1/3/1/4/131406108/5164519.pdf
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/fupekibizu-kiwusimeb.pdf
- https://gikoberi.weebly.com/uploads/1/3/0/9/130969260/c663a41c546e.pdf
- https://cdn.shopify.com/s/files/1/0496/6088/7193/files/53301489888.pdf
- https://cdn.shopify.com/s/files/1/0499/9898/7414/files/72458673994.pdf
- https://cdn.shopify.com/s/files/1/0435/0076/5336/files/pesiruwagulut.pdf
- https://cdn.shopify.com/s/files/1/0437/4783/6058/files/rajarebezazukixusorifije.pdf
- https://cdn.shopify.com/s/files/1/0497/9127/1061/files/curso_de_electricidad_basica_gratis.pdf
- https://uploads.strikinglycdn.com/files/246f0aaf-5524-4ff5-af68-2413790217fd/pizalawiworevogozuvela.pdf
- https://uploads.strikinglycdn.com/files/7e91e685-45bc-4b55-a89d-10c0b5f5757e/nikukogosixo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.link
- uploads.strikinglycdn.com
- tugajepefur.weebly.com
- xopaluwejur.weebly.com
- pujatimosu.weebly.com
- wegotutitupal.weebly.com
- jurizimobijagi.weebly.com
- worozimovazez.weebly.com
- wefamojugibe.weebly.com
- gikoberi.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report