SUSPICIOUS — normal_5f950e6a1bb52.pdf
SUSPICIOUS — normal_5f950e6a1bb52.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
299ce23c4f866483e2c0319299aea05ee0033cb2634552284b57f7858823f40b - SHA-1:
bab2aa7332ff1335afc229f6bf444e783833bfe8 - MD5:
9713f31b5eb52721e717d6d5eda8b199 - ssdeep:
768:UvgGzpD2+Cccamep7ArhXRQPVcx/+4XEAFmui8UjQ8cXeohO4O:9GF6ABpMSQ8eeYO4O - TLSH:
T122327CF350E7DD4C3A869B03AEAE255D848AD6496132AB944588773CC0B837E3F11E60 - Submitted as: normal_5f950e6a1bb52.pdf
- File type: pdf · Size: 44355 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/2ced9c5e-24f1-44bf-900a-18220fe74012/cphq_exam_secrets_study_guide.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.ru/123?keyword=calibri+font+free+download+for+android, https://cdn-cms.f-static.net/uploads/4383917/normal_5f8e5f00b9228.pdf, https://cdn-cms.f-static.net/uploads/4365639/normal_5f871c75469e4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=calibri+font+free+download+for+android
- https://cdn-cms.f-static.net/uploads/4383917/normal_5f8e5f00b9228.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f871c75469e4.pdf
- https://cdn-cms.f-static.net/uploads/4374537/normal_5f8caa104c4d4.pdf
- https://cdn-cms.f-static.net/uploads/4381318/normal_5f8c38f7a4b6d.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f877bd538e5b.pdf
- https://cdn-cms.f-static.net/uploads/4375696/normal_5f91f93904af9.pdf
- https://cdn-cms.f-static.net/uploads/4370059/normal_5f8889c5f319b.pdf
- https://uploads.strikinglycdn.com/files/2ced9c5e-24f1-44bf-900a-18220fe74012/cphq_exam_secrets_study_guide.pdf
- https://uploads.strikinglycdn.com/files/099d063f-7706-4d32-835c-50973de5df7e/35015416679.pdf
- https://jaserasozupog.weebly.com/uploads/1/3/1/4/131454215/56c3a7aab.pdf
- https://zuxizakubapepo.weebly.com/uploads/1/3/4/3/134317428/a4fce.pdf
- https://noxepelobisuse.weebly.com/uploads/1/3/1/8/131871648/a2b7578c594.pdf
- https://uploads.strikinglycdn.com/files/2ec7a991-bf09-4c83-b80f-444fa0b5ab5d/58854475025.pdf
- https://uploads.strikinglycdn.com/files/fdfb72ef-536e-4630-aae3-6491cf406dc2/all_things_algebra_gina_wilson.pdf
- https://uploads.strikinglycdn.com/files/c3857abf-62b7-4648-9422-b3352c94ecb9/topax.pdf
- https://uploads.strikinglycdn.com/files/df8e69ec-e30c-4f89-998c-331ba5a73cff/15890753510.pdf
- https://uploads.strikinglycdn.com/files/a0bbfd82-ec6a-432d-9ebc-44c53e7cf4fb/guriliredukidabaluferoked.pdf
- https://cdn-cms.f-static.net/uploads/4386609/normal_5f9393ec6694c.pdf
- https://cdn-cms.f-static.net/uploads/4376369/normal_5f8a4d26277f8.pdf
- https://cdn-cms.f-static.net/uploads/4376379/normal_5f94bf5eac667.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ttraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- jaserasozupog.weebly.com
- zuxizakubapepo.weebly.com
- noxepelobisuse.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report