SUSPICIOUS — normal_5f9297b6b3853.pdf
SUSPICIOUS — normal_5f9297b6b3853.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3340dc3741e771404839ac91ba15da9fd3b3314db65be5fe6344edb77a17c52f - SHA-1:
965ba275b64a7f9ac97e058d75fc007298329d65 - MD5:
f7d7457ee53687e1435d8c3c64ea2b91 - ssdeep:
768:/HgGzpDTp+qAU94g9u86EqEIROaXlctFBIruqMbsjoC+xoLbYteCt3aa1Veu:4GFnphyXlcZIr0+oLGLbY53DVeu - TLSH:
T172338CF350EBED4CBA8A9B13ADAA15696089C78C6136D76015CC672CC47C2BE7F10861 - Submitted as: normal_5f9297b6b3853.pdf
- File type: pdf · Size: 48911 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/d3cbe665-2e5c-4006-8635-c0d2ab58ac86/mugen.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.me/123?keyword=system+restore+android+tablet, https://uploads.strikinglycdn.com/files/d3cbe665-2e5c-4006-8635-c0d2ab58ac86/mugen.pdf, https://uploads.strikinglycdn.com/files/0bf330f8-c38b-485b-91fa-5f03bc8aa2ea/57936026926.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=system+restore+android+tablet
- https://uploads.strikinglycdn.com/files/d3cbe665-2e5c-4006-8635-c0d2ab58ac86/mugen.pdf
- https://uploads.strikinglycdn.com/files/0bf330f8-c38b-485b-91fa-5f03bc8aa2ea/57936026926.pdf
- https://uploads.strikinglycdn.com/files/f271649a-d403-48e4-a173-022ca26e9e48/jerivobunositekojezol.pdf
- https://uploads.strikinglycdn.com/files/d840b14b-3956-4d29-95f9-c89b313bd95b/dalate.pdf
- https://uploads.strikinglycdn.com/files/f0a16bef-f28e-49e4-9ef3-0615ec3ea15e/zawukobak.pdf
- https://s3.amazonaws.com/jamokaroxoj/kogetotorifigujazewigude.pdf
- https://s3.amazonaws.com/pazifetanegapu/blank_bingo_cards_4x4.pdf
- https://s3.amazonaws.com/sugowubuf/12229757623.pdf
- https://s3.amazonaws.com/tadovu/navifabulolobogakutimiv.pdf
- https://s3.amazonaws.com/subud/personality_disorders_dsm_5.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f86f5349d35d.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f8e1fa94ca38.pdf
- https://cdn-cms.f-static.net/uploads/4370052/normal_5f8dea6940613.pdf
- https://cdn-cms.f-static.net/uploads/4380695/normal_5f927bc4dbd19.pdf
- https://cdn-cms.f-static.net/uploads/4368953/normal_5f89163c7c9ae.pdf
- https://cdn.shopify.com/s/files/1/0431/9245/1232/files/depuzal.pdf
- https://cdn.shopify.com/s/files/1/0502/1037/3822/files/xaxodosixilizaxagabokitod.pdf
- https://cdn.shopify.com/s/files/1/0497/9825/0660/files/22061990947.pdf
- https://sujajikozodes.weebly.com/uploads/1/3/1/3/131384638/rojobutu_jenuf_fubajaga_gajom.pdf
- https://laxuruvu.weebly.com/uploads/1/3/1/4/131482832/9f0bdf376.pdf
- https://bedizegoresupa.weebly.com/uploads/1/3/1/3/131379398/3794757.pdf
- https://jivetigaforivuj.weebly.com/uploads/1/3/4/3/134350389/kenitomazodalewik.pdf
- https://rikisuluwujufa.weebly.com/uploads/1/3/1/4/131452938/4af93938d2efd02.pdf
- https://femitinekabel.weebly.com/uploads/1/3/1/4/131437683/bc2bcb788b.pdf
Embedded domains
- ttraff.me
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- cdn.shopify.com
- sujajikozodes.weebly.com
- laxuruvu.weebly.com
- bedizegoresupa.weebly.com
- jivetigaforivuj.weebly.com
- rikisuluwujufa.weebly.com
- femitinekabel.weebly.com
- nazuvunu.weebly.com
- buximinolid.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report