SUSPICIOUS — normal_5f8faf9bb7608.pdf
SUSPICIOUS — normal_5f8faf9bb7608.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
133da716d96962e0ac563be8012bf050606966eaff6c2b50c548045167b5dc39 - SHA-1:
3fda249f12e15111061a53dcafa5617c5c042efd - MD5:
95c71ebf2a3ba4fe3f97365b28e344b7 - ssdeep:
768:ygGzpDRpJCALKPrwXpoyiy3BYpvh61yhvtvHK/pDHr0NOjzUTA28Q2r2C:vGF9pHfRYpp61aFvqxDHr0N4za8Q2rp - TLSH:
T19733ADF350A7EC4C7A8B6F075EAB159D804EC789607A965084DC672DD0BCAED3E50A20 - Submitted as: normal_5f8faf9bb7608.pdf
- File type: pdf · Size: 49662 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f87c7f60-67d7-4b16-a8dd-08f1fdf0ba64/xisoratal.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.link/123?keyword=oil+and+gas+refining+process+pdf, https://uploads.strikinglycdn.com/files/4415ec82-1776-4093-a47c-38e93183c77d/95271548006.pdf, https://uploads.strikinglycdn.com/files/7157a2f2-8b31-4f00-ac45-59763e288466/94689387870.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=oil+and+gas+refining+process+pdf
- https://uploads.strikinglycdn.com/files/4415ec82-1776-4093-a47c-38e93183c77d/95271548006.pdf
- https://uploads.strikinglycdn.com/files/7157a2f2-8b31-4f00-ac45-59763e288466/94689387870.pdf
- https://uploads.strikinglycdn.com/files/d83f8af6-1bca-4bbb-87ad-1326c9559fc1/fonumaw.pdf
- https://cdn-cms.f-static.net/uploads/4370097/normal_5f88871d7bc88.pdf
- https://uploads.strikinglycdn.com/files/f87c7f60-67d7-4b16-a8dd-08f1fdf0ba64/xisoratal.pdf
- https://uploads.strikinglycdn.com/files/ca0de4d0-e3f4-4ecb-9f48-d428f046ebf8/91588156656.pdf
- https://uploads.strikinglycdn.com/files/6404fa51-45a4-480f-8f4b-03c8390ed14f/ruxadefume.pdf
- https://uploads.strikinglycdn.com/files/9a694063-12a1-487e-b880-7b3330843c6a/jajujojizewifizana.pdf
- https://uploads.strikinglycdn.com/files/49d1999f-4d14-4dc5-b0cd-fcfefdf29fcc/nefutiwekujof.pdf
- https://sizukejagu.weebly.com/uploads/1/3/2/6/132681884/wujulafo.pdf
- https://sesuwulot.weebly.com/uploads/1/3/1/4/131438847/nazesari.pdf
- https://cdn.shopify.com/s/files/1/0499/0867/8814/files/zeguzovow.pdf
- https://cdn.shopify.com/s/files/1/0268/8004/9344/files/71954126625.pdf
- https://cdn.shopify.com/s/files/1/0491/7306/9990/files/no_david_no_book.pdf
- https://cdn.shopify.com/s/files/1/0479/6694/5447/files/39040491056.pdf
- https://cdn.shopify.com/s/files/1/0484/6927/8881/files/duvirolezufirezofi.pdf
- https://uploads.strikinglycdn.com/files/527ea57e-428d-4c3f-9e63-2bec580355b0/74485385693.pdf
- https://uploads.strikinglycdn.com/files/a1fc76d8-a724-4a42-bf7e-90b617d7a364/peg_perego_thomas_the_train_ride_on.pdf
- https://uploads.strikinglycdn.com/files/f7afd001-7b1e-4c09-89ca-4e54fcc16fbc/87214977023.pdf
- https://uploads.strikinglycdn.com/files/e1070449-5c5e-4e6d-ad2a-a0174ccf03de/72182206548.pdf
- https://uploads.strikinglycdn.com/files/514a3288-8ecf-477d-9e4c-91874ef8451b/68079711811.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.link
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- sizukejagu.weebly.com
- sesuwulot.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report