SUSPICIOUS — normal_5f991f2c6eb3c.pdf
SUSPICIOUS — normal_5f991f2c6eb3c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
37aa8709a6edf880dbaf610ddd09b11d25d956a167cec623d1d2bffc694face7 - SHA-1:
638463c0f2824f89676e2c5b6de0a2e4a5661ca9 - MD5:
53cbc99b0b0e298b45679c8084f6bf84 - ssdeep:
768:3gGzpDrpuPvMSyLaV1dpgM7UM6aPi6w0VQDTrCBbGAoOmuh:QGFvpup1dJG6rQDgbkOmuh - TLSH:
T1B032AEF754A3ED8C358AAB035DAE25556189C28C22329B9045DC737CD4BC4FE6E21DB0 - Submitted as: normal_5f991f2c6eb3c.pdf
- File type: pdf · Size: 46537 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/44165934-3a45-462c-a887-332a8c46a45d/riwaritopeforepikuli.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.ru/123?keyword=agri-fab+lawn+sweeper+troubleshooting, https://uploads.strikinglycdn.com/files/44165934-3a45-462c-a887-332a8c46a45d/riwaritopeforepikuli.pdf, https://uploads.strikinglycdn.com/files/95516d98-b60c-42b1-a50a-c21e1f08b871/ln46c630k1f_no_backlight.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=agri-fab+lawn+sweeper+troubleshooting
- https://uploads.strikinglycdn.com/files/44165934-3a45-462c-a887-332a8c46a45d/riwaritopeforepikuli.pdf
- https://uploads.strikinglycdn.com/files/95516d98-b60c-42b1-a50a-c21e1f08b871/ln46c630k1f_no_backlight.pdf
- https://uploads.strikinglycdn.com/files/c7ff0bb1-a3d8-4ec3-bfb7-2148e09684fc/96156965763.pdf
- https://uploads.strikinglycdn.com/files/ba906f28-d625-48ca-ae79-116f3b74d358/hvac_troubleshooting_test.pdf
- https://s3.amazonaws.com/bisute/calculus_1_problems_and_solutions.pdf
- https://s3.amazonaws.com/lanorolowu/bilateral_agreement.pdf
- https://s3.amazonaws.com/zonivezada/java_tutorial_tutorials_point.pdf
- https://s3.amazonaws.com/xanebavifamopez/nexusifegodokip.pdf
- https://s3.amazonaws.com/fasanag/padre_malachi_martin.pdf
- https://uploads.strikinglycdn.com/files/9e1554b0-9220-443d-8d19-2edf1c5a4f88/80981666131.pdf
- https://uploads.strikinglycdn.com/files/002936eb-b641-4c9e-8bbf-967e36b1d79b/7_deadly_sins_porn_comic.pdf
- https://uploads.strikinglycdn.com/files/fdfaf8ed-4fbc-42ad-8658-e808e4883596/83731007348.pdf
- https://uploads.strikinglycdn.com/files/3bfa6592-4961-444d-a2e5-3fcb3d7afd16/bunezavibojutilegerel.pdf
- https://xelabuxu.weebly.com/uploads/1/3/4/2/134235382/4520261.pdf
- https://kezobonuduwu.weebly.com/uploads/1/3/4/4/134457579/sowipov-fejosenovoviten-dogibi-duzataxemepo.pdf
- https://uploads.strikinglycdn.com/files/063a793f-207a-47c6-897e-d3a30b481084/yoshi_island_2_snes.pdf
- https://uploads.strikinglycdn.com/files/6647ac62-7d08-4df5-aef5-089a313009d8/75698296973.pdf
- https://uploads.strikinglycdn.com/files/0bfc8004-98ae-45c8-8a84-57f899df0808/libro_de_informatica_3_secundaria.pdf
- https://cdn.shopify.com/s/files/1/0496/0285/5064/files/gesunumo.pdf
- https://cdn.shopify.com/s/files/1/0477/6483/2412/files/using_the_pythagorean_theorem_answer_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ttraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- xelabuxu.weebly.com
- kezobonuduwu.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report