SUSPICIOUS — assessment_guide_houghton_mifflin_grade_5_answer_key.pdf
SUSPICIOUS — assessment_guide_houghton_mifflin_grade_5_answer_key.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
233300de6767882d3ff14754f59e30142c97a5a03e70ad0929cf3aac1eaf6cd7 - SHA-1:
e9f1c916076834c76da0483de0c7f4a10efdb674 - MD5:
18b89a2d42b6e26513ea408c81478c22 - ssdeep:
3072:kFYWGbLhGE4O383Myl+gmsGgmD65lNwVp:clAV/B7yggzGfyuf - TLSH:
T1673AD0F350D3ED0C75CE9B832AAF24AAA68D93885431A71409D97A6EC47C37C7F10990 - Submitted as: assessment_guide_houghton_mifflin_grade_5_answer_key.pdf
- File type: pdf · Size: 101241 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/cb2c8eff-aa15-4e6b-8b0a-87fbb866b92c/fulenowexokenut.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=assessment+guide+houghton+mifflin+grade+5+answer+key, https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/555469.pdf, https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/gabemomigipenaguv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=assessment+guide+houghton+mifflin+grade+5+answer+key
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/555469.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/gabemomigipenaguv.pdf
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/kufulidagagalazupowu.pdf
- https://xusawoji.weebly.com/uploads/1/3/0/7/130739635/neramadubot_xugenotuput.pdf
- https://digafixi.weebly.com/uploads/1/3/0/7/130776371/noduke.pdf
- https://gimelukisisira.weebly.com/uploads/1/3/4/0/134040832/jejetes-wofikigoribad-namematasavilav.pdf
- https://wuvirinofibugiz.weebly.com/uploads/1/3/1/0/131070402/986ca1.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/2499678.pdf
- https://s3.amazonaws.com/pajukovuxetu/rofafikedirokerafegepiz.pdf
- https://s3.amazonaws.com/pazifetanegapu/air_pollution_ppt.pdf
- https://s3.amazonaws.com/salosibejodod/5787236626.pdf
- https://s3.amazonaws.com/sitok/adobe_greyed_out.pdf
- https://s3.amazonaws.com/felasorarabipis/16779432207.pdf
- https://s3.amazonaws.com/dadupawo/ectomorph_diet.pdf
- https://s3.amazonaws.com/henghuili-files/pharmaceutical_bioassays_methods_and_applications.pdf
- https://cdn-cms.f-static.net/uploads/4386361/normal_5f8e942d0aa5c.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f89243374aa0.pdf
- https://cdn-cms.f-static.net/uploads/4367920/normal_5f8a4b57add52.pdf
- https://uploads.strikinglycdn.com/files/cb2c8eff-aa15-4e6b-8b0a-87fbb866b92c/fulenowexokenut.pdf
- https://uploads.strikinglycdn.com/files/c195768c-4f4e-401b-b096-ca35c453db6e/59171365020.pdf
- https://uploads.strikinglycdn.com/files/f7cfd191-6ccd-4442-9284-3a875e1492c4/gewegafesasijevevujorela.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- sokuvotaboraj.weebly.com
- kabudededawizo.weebly.com
- wefamojugibe.weebly.com
- xusawoji.weebly.com
- digafixi.weebly.com
- gimelukisisira.weebly.com
- wuvirinofibugiz.weebly.com
- rabifupokuwu.weebly.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s.ch
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- q:\yl
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report