SUSPICIOUS — normal_5f941ac773a3d.pdf
SUSPICIOUS — normal_5f941ac773a3d.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
f4ad21819510405c7456ab4425d9c3b09f0256ad55d2c4d72a05c958d07436f5 - SHA-1:
8e12413317811e485ea2964f9a7af4f7e7ef02c3 - MD5:
ed31f9c5b6c43bf4c123feb4cdffa5d5 - ssdeep:
768:6gGzpDVoSnMSxhwCe0nWsNdajxiQFgDekDBiRMCfKWe8p7LrbUaH3:nGFZyPCDtMRMCSWlrbUaH3 - TLSH:
T10833AFF34497ED4C7E86A753ADE618687089C78CA133A76044883F3CD46C6BE7E64960 - Submitted as: normal_5f941ac773a3d.pdf
- File type: pdf · Size: 49402 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.cc/123?keyword=descargar+editor+pdf+portable+full, https://uploads.strikinglycdn.com/files/1ba91bdf-8ec5-48cc-a7ab-2b28f0d065d9/46189067306.pdf, https://uploads.strikinglycdn.com/files/788e42b6-1692-4704-a684-a18ab744d31f/zunok.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=descargar+editor+pdf+portable+full
- https://uploads.strikinglycdn.com/files/1ba91bdf-8ec5-48cc-a7ab-2b28f0d065d9/46189067306.pdf
- https://uploads.strikinglycdn.com/files/788e42b6-1692-4704-a684-a18ab744d31f/zunok.pdf
- https://uploads.strikinglycdn.com/files/d28c2feb-082f-4964-a4f3-300029a92366/58453598922.pdf
- https://s3.amazonaws.com/gavexilatuvitaz/common_abbreviations_and_acronyms.pdf
- https://s3.amazonaws.com/xanebavifamopez/reading_activities_for_esl_students.pdf
- https://s3.amazonaws.com/fujadabez/protein_structure_levels_of_protein_structure.pdf
- https://s3.amazonaws.com/pazifetanegapu/derajat_asma_pada_anak.pdf
- https://s3.amazonaws.com/mijedusovineti/fabaluzutu.pdf
- https://cdn-cms.f-static.net/uploads/4373768/normal_5f90b663c9e07.pdf
- https://cdn-cms.f-static.net/uploads/4367648/normal_5f9206d80aba7.pdf
- https://cdn-cms.f-static.net/uploads/4373259/normal_5f8c9dbe64b22.pdf
- https://uploads.strikinglycdn.com/files/45d889fa-ca6f-4887-bf05-bde8e8b3d80f/82418442507.pdf
- https://uploads.strikinglycdn.com/files/030ab1f1-08c1-4835-a271-6dde15e12e33/urchins_en_action_skyrim.pdf
- https://s3.amazonaws.com/lijopavexanuse/rudobitosanuvaxuwodukuxir.pdf
- https://s3.amazonaws.com/fedufiporara/xedemomazazetedixelafek.pdf
- https://s3.amazonaws.com/dukajevo/dafovowovagipogujukatoko.pdf
- https://s3.amazonaws.com/vetamedisoz/jaxosovowodinox.pdf
- https://cdn-cms.f-static.net/uploads/4389604/normal_5f8d94fb3a857.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f930736e57b3.pdf
- https://cdn-cms.f-static.net/uploads/4366324/normal_5f87a1c87bb9e.pdf
- https://cdn-cms.f-static.net/uploads/4367277/normal_5f878777d6aab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.cc
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report