SUSPICIOUS — normal_5f8b688f893b4.pdf
SUSPICIOUS — normal_5f8b688f893b4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ff9dc5d51807614725548f3f9e56c536a100af628731590412c15af85e46250d - SHA-1:
86cc988f59f55e9ebd433e52d03bf4d9f75d9451 - MD5:
18282c6e321fcfc4302893434372b09e - ssdeep:
768:ogGzpDQpBb5tONrYnaDVwP0T4WC55RMmSToeeU+qIVPxMeLAz3BUoo4FESPqZmy8:lGFkp5xG5E73qIVPxMEAyoo4FDKrY+UV - TLSH:
T139329EF71097EE4C7A8A9B436CAA21E6D0CB87C8B1A35750049C376CA4FC5AC7ED4460 - Submitted as: normal_5f8b688f893b4.pdf
- File type: pdf · Size: 47018 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ttraff.com/123?keyword=m-audio+midisport+2x2+ae+usb+manual, https://uploads.strikinglycdn.com/files/679a78f8-b087-49db-89db-177584c22f05/74549246641.pdf, https://uploads.strikinglycdn.com/files/18fc5e53-1334-4689-8ce9-bad90eee723b/xatewixupitumopenurosiwi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=m-audio+midisport+2x2+ae+usb+manual
- https://uploads.strikinglycdn.com/files/679a78f8-b087-49db-89db-177584c22f05/74549246641.pdf
- https://uploads.strikinglycdn.com/files/18fc5e53-1334-4689-8ce9-bad90eee723b/xatewixupitumopenurosiwi.pdf
- https://uploads.strikinglycdn.com/files/21754778-25fb-4e99-86e3-a59452cb284b/56930933762.pdf
- https://uploads.strikinglycdn.com/files/e1dfdbfd-11aa-4951-aa77-8d7a594c8509/44741958251.pdf
- https://cdn-cms.f-static.net/uploads/4368471/normal_5f8a6befbd346.pdf
- https://cdn-cms.f-static.net/uploads/4371543/normal_5f89377e55fff.pdf
- https://cdn-cms.f-static.net/uploads/4369173/normal_5f88ae7788288.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f870915dd875.pdf
- https://cdn.shopify.com/s/files/1/0438/1917/2000/files/big_tower_tiny_square_music.pdf
- https://cdn.shopify.com/s/files/1/0484/0990/3272/files/kujaligojiwesex.pdf
- https://cdn-cms.f-static.net/uploads/4367297/normal_5f87761d978a0.pdf
- https://cdn-cms.f-static.net/uploads/4366639/normal_5f88b4ab25982.pdf
- https://cdn-cms.f-static.net/uploads/4378857/normal_5f8b63ca811ee.pdf
- https://cdn-cms.f-static.net/uploads/4366405/normal_5f87400dbd514.pdf
- https://cdn-cms.f-static.net/uploads/4366646/normal_5f8b3ee008efb.pdf
- https://tidoxanarapora.weebly.com/uploads/1/3/2/7/132710787/pifesebi_gowiwawufulini_fubatimexofu_jelabu.pdf
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/wilajonasadavid-vowojinujimep-tarigux-kapiwak.pdf
- https://vixijusodu.weebly.com/uploads/1/3/0/7/130776714/somizelesowuzowewowa.pdf
- https://uploads.strikinglycdn.com/files/f7362acf-1ce1-4d53-9fde-d217dd2b5b87/67579367979.pdf
- https://uploads.strikinglycdn.com/files/ea0337a4-2676-4b88-b88b-374c7981e8fc/581141192.pdf
- https://uploads.strikinglycdn.com/files/408ccc0b-6eb3-45e5-831f-d9c98b573310/fofazaw.pdf
- https://uploads.strikinglycdn.com/files/64157566-a418-4e60-b8cc-8233e0f7555c/86443430378.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- tidoxanarapora.weebly.com
- xazapadikud.weebly.com
- vixijusodu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report