SUSPICIOUS — normal_5f93e7a594772.pdf
SUSPICIOUS — normal_5f93e7a594772.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
fc0a07e5ba423f38cbc3aacaeedfa65ee603b9b4c0f955863c503879406be3f6 - SHA-1:
64e1a0159c68441663bc271833ae00ec470ccba4 - MD5:
de6a491d6e439c3a263ca515e767748c - ssdeep:
1536:dGF1GXEwZiDsKP669iQzAjmd7Jcl8sWN0YPWGaCYXuxdP:gF1GXEwZiDBy6917JcudyYnp6A - TLSH:
T15735BFF350D7ED9C7ACD6B43EDB719591149C38861329BA00888BB6DC4BC6EC7E509A0 - Submitted as: normal_5f93e7a594772.pdf
- File type: pdf · Size: 61689 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.club/123?keyword=android+dlna+client+chromecast, https://uploads.strikinglycdn.com/files/5d92ec35-d0fa-47a1-94a8-2922e735fcc3/94258784159.pdf, https://uploads.strikinglycdn.com/files/89d05949-0b8c-4ad2-8d12-c8011ce3c8ea/51808847649.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=android+dlna+client+chromecast
- https://uploads.strikinglycdn.com/files/5d92ec35-d0fa-47a1-94a8-2922e735fcc3/94258784159.pdf
- https://uploads.strikinglycdn.com/files/89d05949-0b8c-4ad2-8d12-c8011ce3c8ea/51808847649.pdf
- https://uploads.strikinglycdn.com/files/a88fe51d-71cd-49e6-bd56-670a54f93434/luzed.pdf
- https://uploads.strikinglycdn.com/files/6eb0f159-90e3-43a2-bec1-c1d0a5df8d71/waluf.pdf
- https://uploads.strikinglycdn.com/files/6dbb32a0-d20a-4ae7-9f80-435928926276/718953377.pdf
- https://uploads.strikinglycdn.com/files/5ed81cef-b6be-496e-8e59-801c73364358/zemizovat.pdf
- https://uploads.strikinglycdn.com/files/6bb32c28-c726-4d2b-899c-facd0ad8b9c7/25622215888.pdf
- https://uploads.strikinglycdn.com/files/2320f9be-1777-4bc9-869a-3c3131f2b8df/dizexefekisego.pdf
- https://uploads.strikinglycdn.com/files/2bd8ca11-3adc-4ae3-ab95-b4c3075754d5/dovomelopituzogose.pdf
- https://kusebedanosude.weebly.com/uploads/1/3/1/1/131163667/3909083.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/6ab2ea7.pdf
- https://nulixedupalaz.weebly.com/uploads/1/3/0/7/130739510/tisug.pdf
- https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/2e70f709551c255.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/2467235.pdf
- https://uploads.strikinglycdn.com/files/facf1177-4295-40c9-8050-d4244002f80c/impossible_quiz_2_question_7.pdf
- https://uploads.strikinglycdn.com/files/171d6ff5-6e92-4ef6-9af8-cc4f999fd9bf/nijawufolajajo.pdf
- https://uploads.strikinglycdn.com/files/cd5c0de4-84fd-4b8e-8b97-aac503efea14/52157857359.pdf
- https://uploads.strikinglycdn.com/files/25344b4f-8581-4389-8ab3-b8001010587a/mozajifabojelozivur.pdf
- https://uploads.strikinglycdn.com/files/d0cc455e-2438-4974-a26d-e850ee991ca1/94398934594.pdf
- https://s3.amazonaws.com/wilugugo/51050944530.pdf
- https://s3.amazonaws.com/netinuwa/77685447052.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.club
- uploads.strikinglycdn.com
- kusebedanosude.weebly.com
- ditiwudo.weebly.com
- nulixedupalaz.weebly.com
- jonukejunuxesa.weebly.com
- jawowigo.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report