SUSPICIOUS — normal_5f8a7a088b0ad.pdf
SUSPICIOUS — normal_5f8a7a088b0ad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
085138ac14b42e8aa4a968b1a2e53b82a0c3d550500d26c091fe3f1908b151f6 - SHA-1:
b586f9361c7ccb14fccd0e8c1ef5a8cbcb14468e - MD5:
579c1af83d649386f239b73649c8569c - ssdeep:
1536:qGFZpChwh+KVXY9gBjzRfEjs6e8Ww3h7Mku5:TFZpSwh+KVyKvRIs6tJ31MZ - TLSH:
T1CF348EF31067EC8C7B8F9B436DAB119A654BC28C61379B600588676CD5BC6FE2F00A51 - Submitted as: normal_5f8a7a088b0ad.pdf
- File type: pdf · Size: 52465 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/19686296-0823-4890-aeb1-3b387199c37c/gesopuradejufa.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.me/123?keyword=debussy+reflets+dans+l%2527eau+pdf, https://cdn.shopify.com/s/files/1/0427/5293/4044/files/hamilton_beach_espresso_maker_40729_manual.pdf, https://cdn.shopify.com/s/files/1/0486/0225/1432/files/bob_evans_coleslaw_ingredients.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=debussy+reflets+dans+l%2527eau+pdf
- https://cdn.shopify.com/s/files/1/0427/5293/4044/files/hamilton_beach_espresso_maker_40729_manual.pdf
- https://cdn.shopify.com/s/files/1/0486/0225/1432/files/bob_evans_coleslaw_ingredients.pdf
- https://cdn.shopify.com/s/files/1/0430/0003/7527/files/87438798309.pdf
- https://xijonezamo.weebly.com/uploads/1/3/1/4/131407630/7114657.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/lanadez.pdf
- https://fotejisatowonu.weebly.com/uploads/1/3/2/3/132302873/8829922.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/8260600.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/3722212.pdf
- https://cdn.shopify.com/s/files/1/0266/7744/4777/files/reading_like_a_writer_francine_prose_download.pdf
- https://cdn.shopify.com/s/files/1/0496/1180/0729/files/white_sushi_fortnite.pdf
- https://cdn.shopify.com/s/files/1/0433/1054/7099/files/gametest_roblox_com.pdf
- https://cdn.shopify.com/s/files/1/0500/4489/5392/files/68795784591.pdf
- https://uploads.strikinglycdn.com/files/19686296-0823-4890-aeb1-3b387199c37c/gesopuradejufa.pdf
- https://uploads.strikinglycdn.com/files/967571b5-d8cc-4974-882a-5e91ae987d94/79594688943.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f88d90bd2a2c.pdf
- https://cdn-cms.f-static.net/uploads/4369933/normal_5f88aceb28cb1.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f884bf0a6413.pdf
- https://cdn-cms.f-static.net/uploads/4377380/normal_5f8a53594ebe7.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f87bb5165683.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/jixidused.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/kovesulowapo-tapufovus.pdf
- https://goduvozimaku.weebly.com/uploads/1/3/1/3/131380582/gitotirajixuwinaf.pdf
- https://jivexine.weebly.com/uploads/1/3/1/3/131380908/gomanezibarubagujik.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/nefofelutitaw_nesabemexubufo.pdf
Embedded domains
- ttraff.me
- cdn.shopify.com
- xijonezamo.weebly.com
- guwomenod.weebly.com
- fotejisatowonu.weebly.com
- jawowigo.weebly.com
- jawasolasazilem.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- jatorogerujew.weebly.com
- xojerajap.weebly.com
- goduvozimaku.weebly.com
- jivexine.weebly.com
- juragubiv.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report