SUSPICIOUS — normal_5f8a10e0d32e1.pdf
SUSPICIOUS — normal_5f8a10e0d32e1.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3d6d4aa3f33b19fdb6a21697b4eb55e174b3021ed6fee8e8c5b35a5bce37bef1 - SHA-1:
771ca3f0b0e79e81a08e895108668055b718fb8e - MD5:
9ce4d95295c152fb9ca6bd7f709e3d32 - ssdeep:
768:IgGzpD2mp2PvgWHe7lqjXNOSzobUy2IIqfXMKW/H8HLxiixOMlByutEWIG:FGFCmp2nj+iTqiv8HLLlMutEWIG - TLSH:
T15B338DF39097ED8C7A8B6F03AAE7155AA54BC38D6076D7A00988372CD07C6BC7D00A51 - Submitted as: normal_5f8a10e0d32e1.pdf
- File type: pdf · Size: 49730 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a2f29e3a-1aad-4565-92db-1e15bcb09a50/japagenox.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.link/123?keyword=schlage+mortise+lock+installation+instructions, https://cdn.shopify.com/s/files/1/0268/7080/8765/files/70894240952.pdf, https://cdn.shopify.com/s/files/1/0494/2253/2775/files/eso_mages_guild_quests_requirements.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=schlage+mortise+lock+installation+instructions
- https://cdn.shopify.com/s/files/1/0268/7080/8765/files/70894240952.pdf
- https://cdn.shopify.com/s/files/1/0494/2253/2775/files/eso_mages_guild_quests_requirements.pdf
- https://cdn.shopify.com/s/files/1/0497/9225/4105/files/football_logo_quiz_answers.pdf
- https://uploads.strikinglycdn.com/files/a2f29e3a-1aad-4565-92db-1e15bcb09a50/japagenox.pdf
- https://uploads.strikinglycdn.com/files/464d5948-35fa-4d59-b998-81ed9c9a53c6/kenon.pdf
- https://uploads.strikinglycdn.com/files/b5a69b78-fc5a-4c8a-b132-f41bbbe81fa8/piledigajokovujutugetunak.pdf
- https://uploads.strikinglycdn.com/files/122e1bfe-830e-4eb1-8c70-a64f48971380/nopokizavatawe.pdf
- https://uploads.strikinglycdn.com/files/713f6a3e-8197-4fef-a815-0c098bd0493f/raregugexusixabajo.pdf
- https://cdn.shopify.com/s/files/1/0430/8389/0850/files/91793444457.pdf
- https://cdn.shopify.com/s/files/1/0499/8896/0406/files/3.7_jeep_vacuum_diagram.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/5026136.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/ruvewa.pdf
- https://uploads.strikinglycdn.com/files/b8fb328a-1af7-4a11-9423-6956e0aa743c/sidodovatapo.pdf
- https://uploads.strikinglycdn.com/files/9e21c9ba-4b09-4f16-b187-6c9bdfeb2285/43973623299.pdf
- https://uploads.strikinglycdn.com/files/c8713128-2e8e-4cc0-8e6f-1d3686ebeb54/27052165107.pdf
- https://uploads.strikinglycdn.com/files/23665679-10e1-40b5-ba14-236d18dbff00/69226836964.pdf
- https://uploads.strikinglycdn.com/files/23c4a3e4-4811-44e1-8d78-390d8da127cb/25938182274.pdf
- https://cdn.shopify.com/s/files/1/0481/4906/9991/files/san_mateo_high_canvas.pdf
- https://cdn.shopify.com/s/files/1/0432/5025/3984/files/30300412405.pdf
- https://cdn.shopify.com/s/files/1/0495/9961/1047/files/five_minute_relationship_repair.pdf
- https://cdn.shopify.com/s/files/1/0484/9260/9686/files/girem.pdf
- https://cdn.shopify.com/s/files/1/0435/5008/1183/files/kusivetabepupi.pdf
- http://w3.security
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.link
- cdn.shopify.com
- uploads.strikinglycdn.com
- babikovinemixe.weebly.com
- ditiwudo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- w3.security
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report