SUSPICIOUS — normal_5f9462c601323.pdf
SUSPICIOUS — normal_5f9462c601323.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
fde0e1e16ef5b6b597762a67f7e67403ffeeb07ff5043f5ac0def37b08195863 - SHA-1:
20c273f57caccc7217570dbe379ec9b3932bc0d1 - MD5:
29a7cc2a8111978be68e56406c2fab5d - ssdeep:
768:8gGzpDxaPWd3toH3BjuIFAViBlpo5mShemCAiul:ZGFtHtoH3VEi651emCJul - TLSH:
T10B317CF310ABED4C7B8F5B07AEA7119A614AC3896136DA20458C772CC47CAFD6F10951 - Submitted as: normal_5f9462c601323.pdf
- File type: pdf · Size: 39617 bytes
- Verdict: suspicious (35/100)
Detections (2 of 53 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://ttraff.link/123?keyword=maths+mastery+year+2+worksheets, https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/zuwojutodabit.pdf, https://bujupovira.weebly.com/uploads/1/3/4/4/134472582/letuwos_jodugadiwax_dafamalon.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=maths+mastery+year+2+worksheets
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/zuwojutodabit.pdf
- https://bujupovira.weebly.com/uploads/1/3/4/4/134472582/letuwos_jodugadiwax_dafamalon.pdf
- https://xifamosavujefiv.weebly.com/uploads/1/3/4/4/134457952/1971163.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/9031774.pdf
- https://sopodepewujo.weebly.com/uploads/1/3/4/3/134340903/xifafojolobuvezebenu.pdf
- https://uploads.strikinglycdn.com/files/bda0c034-f405-48bb-a07f-523471c1cbaf/12048222721.pdf
- https://cdn.shopify.com/s/files/1/0481/5654/1077/files/zebepefatakelodobanozavif.pdf
- https://cdn.shopify.com/s/files/1/0440/1673/0277/files/formato_dc_3.pdf
- https://cdn.shopify.com/s/files/1/0483/1117/3275/files/lara_croft_game_hack_apk.pdf
- https://rudofodirofebas.weebly.com/uploads/1/3/0/7/130739781/vebelovojar-menuvaropewuro.pdf
- https://norumevi.weebly.com/uploads/1/3/0/9/130969469/d93cd6.pdf
- https://temazojirilezin.weebly.com/uploads/1/3/2/3/132302863/morutafimoxemum-segaxupetaj-wegavaz-zipiweb.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/nijefakipo_fijesafelajesow_gumujaz.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/2161657.pdf
- https://dagigokes.weebly.com/uploads/1/3/0/7/130739756/5e20c36439039.pdf
- https://tenagudewujuga.weebly.com/uploads/1/3/1/1/131164273/881570.pdf
- https://nitiruminaxodax.weebly.com/uploads/1/3/0/7/130738633/32ff583ac1467.pdf
- https://joleziravakejar.weebly.com/uploads/1/3/4/4/134460301/wogafafo.pdf
- https://vumorusumanipav.weebly.com/uploads/1/3/4/2/134234742/1b6f63b888.pdf
- https://uploads.strikinglycdn.com/files/507bbc70-6e44-4a5d-8f14-7a1b42c7d9b3/pezowamiv.pdf
- https://uploads.strikinglycdn.com/files/26ba7c83-73be-4474-87ae-436f0571c451/1523284513.pdf
- https://uploads.strikinglycdn.com/files/a7441920-dde0-4861-9d0e-2f566ad2bf3d/dolarobuziseg.pdf
- https://uploads.strikinglycdn.com/files/4fd3e081-8b75-42cd-8aa9-3c6e50860212/munuzojikekuletirabigimoj.pdf
- https://uploads.strikinglycdn.com/files/83f999a7-4fda-4a10-9bc3-0af2f5d7985e/73102470110.pdf
Embedded domains
- ttraff.link
- digonowokeke.weebly.com
- bujupovira.weebly.com
- xifamosavujefiv.weebly.com
- vuxozajuje.weebly.com
- sopodepewujo.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- rudofodirofebas.weebly.com
- norumevi.weebly.com
- temazojirilezin.weebly.com
- saxibodusazo.weebly.com
- kelobutino.weebly.com
- dagigokes.weebly.com
- tenagudewujuga.weebly.com
- nitiruminaxodax.weebly.com
- joleziravakejar.weebly.com
- vumorusumanipav.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report