SUSPICIOUS — normal_5f8f9483b51b0.pdf
SUSPICIOUS — normal_5f8f9483b51b0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f9f29b162ad9057ef018adf092f6d23866454a77a058e1507b88aa4f953e56b5 - SHA-1:
2d4f54e3846e27bf37336b1eae811f9334c0e850 - MD5:
1d70a77a04ebe5a925b0482cfe65f778 - ssdeep:
768:+gGzpDCpqvwJVpwK6mZeF43+N0lbVXb+Xrd5QzTsFywMK4ijFvdkifwLSjXLMKyl:7GFWpdsFHM8vdMSjC0Q3fXLg8 - TLSH:
T139339DF3109BEE4D3AC34B93ADB716987148C28971329794049C732DA6B86BDBF50870 - Submitted as: normal_5f8f9483b51b0.pdf
- File type: pdf · Size: 48177 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=prestone+radiator+flush+instructions, https://cdn.shopify.com/s/files/1/0501/5247/2764/files/the_high_school_survival_guide_free.pdf, https://cdn.shopify.com/s/files/1/0437/6972/5080/files/insert_alpha_symbol_in_word.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=prestone+radiator+flush+instructions
- https://cdn.shopify.com/s/files/1/0501/5247/2764/files/the_high_school_survival_guide_free.pdf
- https://cdn.shopify.com/s/files/1/0437/6972/5080/files/insert_alpha_symbol_in_word.pdf
- https://cdn.shopify.com/s/files/1/0482/9629/6612/files/kidkraft_disney_cars_table_instructions.pdf
- https://cdn.shopify.com/s/files/1/0496/4515/8564/files/fanexakapuv.pdf
- https://cdn.shopify.com/s/files/1/0429/6146/9599/files/kutarovabote.pdf
- https://cdn-cms.f-static.net/uploads/4369158/normal_5f8ee5a678fd0.pdf
- https://cdn-cms.f-static.net/uploads/4378404/normal_5f8b36e2c0266.pdf
- https://cdn-cms.f-static.net/uploads/4375070/normal_5f8af352aa43f.pdf
- https://cdn-cms.f-static.net/uploads/4387412/normal_5f8f330d3cda0.pdf
- https://cdn-cms.f-static.net/uploads/4372960/normal_5f8e7cdbe8cc4.pdf
- https://cdn-cms.f-static.net/uploads/4374178/normal_5f89f190f15ea.pdf
- https://cdn.shopify.com/s/files/1/0437/7814/6462/files/hotmail_messages_missing_from_inbox.pdf
- https://cdn.shopify.com/s/files/1/0500/3178/8182/files/difference_between_pollution_and_contamination.pdf
- https://cdn.shopify.com/s/files/1/0502/9095/0338/files/73031908722.pdf
- https://cdn.shopify.com/s/files/1/0266/8396/5634/files/human_physiology_the_gastrointestinal_system.pdf
- https://fawefugixizim.weebly.com/uploads/1/3/1/3/131383791/622d8d8599e.pdf
- https://dopuxaponaxu.weebly.com/uploads/1/3/2/6/132695391/549386.pdf
- https://kiseridebajesa.weebly.com/uploads/1/3/1/4/131408791/logunavav_beraleburovege.pdf
- https://uploads.strikinglycdn.com/files/47f90058-c5c5-4261-86b7-2aca919b7270/nelowamafukirefirezawusag.pdf
- https://uploads.strikinglycdn.com/files/1a239fdb-2087-4bf0-81a4-89eeff125ad1/84678024914.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ttraff.link
- cdn.shopify.com
- cdn-cms.f-static.net
- fawefugixizim.weebly.com
- dopuxaponaxu.weebly.com
- kiseridebajesa.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report