SUSPICIOUS — normal_5f96594a95101.pdf
SUSPICIOUS — normal_5f96594a95101.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
f4f140205da0015e162f34391e0b7bb78066d5ad32adee45f17530778464f6cf - SHA-1:
75205a6de70b56d65c52329e1abb01c69499ecb8 - MD5:
af8310e680508407e8b4863622676368 - ssdeep:
768:PgGzpDzpcg9wxOlAW302mcTdKGcl+eA6xoUwlCKPKQzYOQCMcmBDxWypp9OD/+K3:4GF/pO0TKGcliwowubQFBDxWQK/+lu - TLSH:
T158349EF710A7DD8C7AC7AF436EAB1559A049D38C7172E6504588672DC0BC2BD3F50A60 - Submitted as: normal_5f96594a95101.pdf
- File type: pdf · Size: 53801 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/123?keyword=download+multiplayer+for+minecraft+pe+apk, https://uploads.strikinglycdn.com/files/3547e02e-0adc-4834-b266-b332b157faa2/24976221284.pdf, https://uploads.strikinglycdn.com/files/58971453-a166-4539-875f-fba1c368f59d/3642990328.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=download+multiplayer+for+minecraft+pe+apk
- https://s3.amazonaws.com/gogonof/44902061233.pdf
- https://s3.amazonaws.com/sakaburepagase/nijulakodusiwit.pdf
- https://s3.amazonaws.com/liguwubore/78619516750.pdf
- https://s3.amazonaws.com/jazofi/7212027703.pdf
- https://s3.amazonaws.com/nigimul/broken_glass_book.pdf
- https://uploads.strikinglycdn.com/files/3547e02e-0adc-4834-b266-b332b157faa2/24976221284.pdf
- https://uploads.strikinglycdn.com/files/58971453-a166-4539-875f-fba1c368f59d/3642990328.pdf
- https://uploads.strikinglycdn.com/files/4d7e02b8-7a68-4021-98b9-de44733197f2/edd_form_de_2525.pdf
- https://uploads.strikinglycdn.com/files/2625132c-690c-43cf-909a-fdd2fd61230d/49359951230.pdf
- https://uploads.strikinglycdn.com/files/5b97510c-182f-4889-90d6-3cfb65ee5592/xerivoxenaxir.pdf
- https://uploads.strikinglycdn.com/files/6222650f-2f23-41e7-b50b-4fad953a3978/67953000006.pdf
- https://uploads.strikinglycdn.com/files/9d89ca34-9743-404f-8434-65f08a72ba49/70737762015.pdf
- https://uploads.strikinglycdn.com/files/76b489ac-8624-46f3-b0e0-fa1f069ca856/lagonigodaginotum.pdf
- https://uploads.strikinglycdn.com/files/91b4fecf-c702-476d-9fe5-4a97ea8f8705/wozavabibitafenemusiz.pdf
- https://cdn-cms.f-static.net/uploads/4390642/normal_5f959a2430982.pdf
- https://cdn-cms.f-static.net/uploads/4368768/normal_5f88deac1b0b7.pdf
- https://uploads.strikinglycdn.com/files/5f3b23bf-55cd-4f3a-bba1-839b295d49cb/74172606379.pdf
- https://uploads.strikinglycdn.com/files/49c7c0a7-6e81-4e64-a7b0-b3f411f883f6/razozurudilonezedixupe.pdf
- https://uploads.strikinglycdn.com/files/ed24fb39-ea12-49fe-86bc-4bdc47a3ac8b/mapum.pdf
- https://s3.amazonaws.com/luropi/jurnal_pendekatan_behavioristik.pdf
- https://s3.amazonaws.com/nefagolom/psychology_in_hindi_file.pdf
- https://s3.amazonaws.com/wilugugo/bahari_za_mashairi.pdf
- https://s3.amazonaws.com/mijedusovineti/boketobumejifu.pdf
- https://s3.amazonaws.com/leguvefu/comunicar_assertivamente.pdf
Embedded domains
- ttraff.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report