SUSPICIOUS — normal_5f8fcade1bae3.pdf
SUSPICIOUS — normal_5f8fcade1bae3.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e319b41ecb93e5bd69fb47d13dc97ae3303253f11c994d5c834a2cf97bf0ea75 - SHA-1:
f6c4cbc761f0ad41174a5a7492d236830b419049 - MD5:
b486a3ff0994eef61993138d14733500 - ssdeep:
768:ngGzpD2e38w6fzP0y5hRXN4vpgMJwasr2ulrX1y1l+3L4Q3riRibjgfCfysW:gGFCe9qaalrlyqkQ3ECasW - TLSH:
T1EC339DF314E7DE8C7A8AEF13ADAA156A104ED34872369750108C762DC5BC6BDAF10D60 - Submitted as: normal_5f8fcade1bae3.pdf
- File type: pdf · Size: 49579 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/123?keyword=walgreens+photo+app+instructions, https://uploads.strikinglycdn.com/files/f115757d-f775-4c58-884c-67d8ede7cfd7/nefipitumeduxuwetej.pdf, https://uploads.strikinglycdn.com/files/ede98dfc-d96e-42f0-9da1-23a80945e9ff/34348261245.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=walgreens+photo+app+instructions
- https://uploads.strikinglycdn.com/files/f115757d-f775-4c58-884c-67d8ede7cfd7/nefipitumeduxuwetej.pdf
- https://uploads.strikinglycdn.com/files/ede98dfc-d96e-42f0-9da1-23a80945e9ff/34348261245.pdf
- https://uploads.strikinglycdn.com/files/a315f1f3-46fd-4026-8ec8-e2e07626af92/vector_en_equilibrio.pdf
- https://uploads.strikinglycdn.com/files/66834bac-22e2-4988-abb9-2cc8b4d0fe11/73693045799.pdf
- https://uploads.strikinglycdn.com/files/3714585d-c78c-4704-bfa6-de167f973e18/nadugedokowosiwi.pdf
- https://uploads.strikinglycdn.com/files/ac101cad-31c3-46ff-9c14-8ee72bc2a2e0/85277295058.pdf
- https://uploads.strikinglycdn.com/files/ecb0b61e-0c42-433f-931d-d741b02804ec/francisco_alegre_partitura.pdf
- https://uploads.strikinglycdn.com/files/50f41b5c-1151-4eac-9955-9f2dd841bb94/dokipo.pdf
- https://cdn.shopify.com/s/files/1/0440/4012/6614/files/61157923047.pdf
- https://cdn.shopify.com/s/files/1/0268/8670/1238/files/brock_book_of_microorganisms.pdf
- https://cdn.shopify.com/s/files/1/0497/2760/2840/files/wasupikuneviwonu.pdf
- https://uploads.strikinglycdn.com/files/35d99718-a73a-43b1-97fc-c9435238e98b/dragon_age_inquisition_hinterlands_landmarks.pdf
- https://uploads.strikinglycdn.com/files/8400678b-69b1-4b10-b5a3-9a276b66fca6/kurekijagamo.pdf
- https://uploads.strikinglycdn.com/files/bc61d328-5716-42d9-8cb6-a06a2d4d2a36/wozora.pdf
- https://uploads.strikinglycdn.com/files/0a4678ab-c56b-433d-baa6-327f5f4e97bc/79277832765.pdf
- https://uploads.strikinglycdn.com/files/0c1b2646-cd34-4f72-8da8-c8dc5cda7a7f/zukelaves.pdf
- https://cdn-cms.f-static.net/uploads/4366620/normal_5f88c18eebae4.pdf
- https://cdn-cms.f-static.net/uploads/4374369/normal_5f8f7125d0d92.pdf
- https://cdn-cms.f-static.net/uploads/4386824/normal_5f8f3afb2765e.pdf
- https://cdn-cms.f-static.net/uploads/4383688/normal_5f8d0dca67d90.pdf
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f8d1a619af46.pdf
- https://cdn-cms.f-static.net/uploads/4372073/normal_5f8baffbde7fe.pdf
- https://cdn-cms.f-static.net/uploads/4375694/normal_5f8f94af128e1.pdf
- https://cdn-cms.f-static.net/uploads/4372073/normal_5f8bbfaf4d45f.pdf
Embedded domains
- ttraff.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report