SUSPICIOUS — normal_5f8aa5fe2544e.pdf
SUSPICIOUS — normal_5f8aa5fe2544e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
ef56a49e6ef2cf4f68307f83b9f433a3fcdb0e51bbf8e86d5f10c4a7beaf71a7 - SHA-1:
09faa7c855b1d442d51c215ee7900759d037d81d - MD5:
375a8fdbf16d9bc4c5969000d89be0a0 - ssdeep:
1536:uGFZpN68XiIbjgi7TdHPJu/B3u9FBnZ63:XFZpN68XiIbUwHPJupuDt0 - TLSH:
T19B338DF350A3EC4C7A87DF43A9AB295E508ED2495132EB90549C6A7DC4BC7BC3E00A51 - Submitted as: normal_5f8aa5fe2544e.pdf
- File type: pdf · Size: 51146 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=how+to+fix+untrusted+certificate+error+android, https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/sobipidixi.pdf, https://gadigode.weebly.com/uploads/1/3/2/6/132680949/e1f1745c41.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.cc/123?keyword=how+to+fix+untrusted+certificate+error+android
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/sobipidixi.pdf
- https://gadigode.weebly.com/uploads/1/3/2/6/132680949/e1f1745c41.pdf
- https://biwugina.weebly.com/uploads/1/3/1/1/131163984/d643ecff1340038.pdf
- https://tuxitusonodedin.weebly.com/uploads/1/3/0/8/130873989/36e88c2d4b4.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/9b53ec72f.pdf
- https://cdn.shopify.com/s/files/1/0502/9462/0333/files/kirchhoffs_voltage_law_examples.pdf
- https://cdn.shopify.com/s/files/1/0481/6093/1991/files/sadikexepifiveri.pdf
- https://cdn.shopify.com/s/files/1/0481/8052/7258/files/pivefekugegidiso.pdf
- https://cdn-cms.f-static.net/uploads/4369654/normal_5f8a0bbd2ad2d.pdf
- https://cdn-cms.f-static.net/uploads/4370768/normal_5f881c8c48125.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f871dc2df539.pdf
- https://cdn-cms.f-static.net/uploads/4376599/normal_5f8a6f86a3502.pdf
- https://cdn-cms.f-static.net/uploads/4369764/normal_5f87e33ab9d12.pdf
- https://uploads.strikinglycdn.com/files/10f6ef3c-0ab6-4902-adc3-ef0e8861758f/59756243390.pdf
- https://uploads.strikinglycdn.com/files/934f6980-b769-4889-8176-b8a8196833ac/88017240251.pdf
- https://uploads.strikinglycdn.com/files/f616ae30-0191-4e2e-93e9-436777e0e7d3/53182494065.pdf
- https://uploads.strikinglycdn.com/files/6fbd98b4-999c-4dc7-8198-0632b9c334e7/wuzatewi.pdf
- https://uploads.strikinglycdn.com/files/cf71bdc4-0b61-43b2-b7f8-33b94d365ee5/detafavobadipubemuja.pdf
- https://zimiduninu.weebly.com/uploads/1/3/1/6/131637103/fevebixome.pdf
- https://funiwulew.weebly.com/uploads/1/3/2/8/132814073/6c31650.pdf
- https://xifobosakup.weebly.com/uploads/1/3/2/8/132815359/433c4d8cc5e7b.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/4056517.pdf
- https://redunexodozik.weebly.com/uploads/1/3/0/8/130814050/sikutaxudeza-zinilekesoga-mowuwag-pazewosugem.pdf
- https://dokodajibebabek.weebly.com/uploads/1/3/2/3/132302773/suwixumerudivoz.pdf
Embedded domains
- ttraff.cc
- wefamojugibe.weebly.com
- gadigode.weebly.com
- biwugina.weebly.com
- tuxitusonodedin.weebly.com
- mogilifus.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- zimiduninu.weebly.com
- funiwulew.weebly.com
- xifobosakup.weebly.com
- dutitujazekap.weebly.com
- redunexodozik.weebly.com
- dokodajibebabek.weebly.com
- xedaliwim.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report