SUSPICIOUS — normal_5f8b4facad9e4.pdf
SUSPICIOUS — normal_5f8b4facad9e4.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
40c8ec3a6bf7d9b2732610b999b2f12ca11f1ccdea5dfb3e1fb207d88f3fa123 - SHA-1:
a984d785eb1c1c8bb8573ce70290cdf91da45512 - MD5:
f352e51fc965dfb634acae158612659f - ssdeep:
1536:UGFfpg110k2jOvUO45HiwdD/WyXZwO/tXrwMr+N2XIFcDbk/gxWJfSLX:hFfpc6OvUO4hiw5RXGOV7wMr+N2XIFcn - TLSH:
T12C39E0F7548BEE8C79870B439EE62251614AC3C9237297A025CC762DC4F86FD6F40A60 - Submitted as: normal_5f8b4facad9e4.pdf
- File type: pdf · Size: 87233 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5cdab458-54ec-4afb-ba5b-d1a700673a26/fobabufupozuvagilas.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.me/123?keyword=physics+worksheet+lesson+6+projectile+motion, https://gujodoludota.weebly.com/uploads/1/3/2/6/132681740/8342438.pdf, https://xodetawutal.weebly.com/uploads/1/3/0/7/130774968/01fe15f0ea.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=physics+worksheet+lesson+6+projectile+motion
- https://gujodoludota.weebly.com/uploads/1/3/2/6/132681740/8342438.pdf
- https://xodetawutal.weebly.com/uploads/1/3/0/7/130774968/01fe15f0ea.pdf
- https://tenagudewujuga.weebly.com/uploads/1/3/1/1/131164273/deece8dbd8fb1e.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/pubewajuwapuz.pdf
- https://kokexofagisukop.weebly.com/uploads/1/3/2/7/132710589/kabojo-rutovumeme-zemogo.pdf
- https://uploads.strikinglycdn.com/files/5cdab458-54ec-4afb-ba5b-d1a700673a26/fobabufupozuvagilas.pdf
- https://uploads.strikinglycdn.com/files/15da2834-c4ca-43ff-b6f4-c059f9881dd3/xekamujovuwalogetef.pdf
- https://uploads.strikinglycdn.com/files/bafa5601-98e8-4e2d-82ac-6448d0af81d2/93655874467.pdf
- https://uploads.strikinglycdn.com/files/a64c1dcf-e5b0-461e-b544-805b07f0e0f2/rurazuk.pdf
- https://uploads.strikinglycdn.com/files/6ae91ba2-0bfa-4666-8229-9164e683b8ec/doruwurir.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/belapigojat.pdf
- https://dedotomonifagax.weebly.com/uploads/1/3/1/6/131606429/zewafiraserad_bikel_tisev_minuv.pdf
- https://cdn.shopify.com/s/files/1/0428/7509/3159/files/ghost_jason_reynolds.pdf
- https://cdn.shopify.com/s/files/1/0496/0675/4470/files/xixurezatipozekefodomubu.pdf
- https://cdn.shopify.com/s/files/1/0498/7342/0455/files/bunga_tapak_dara.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.me
- gujodoludota.weebly.com
- xodetawutal.weebly.com
- tenagudewujuga.weebly.com
- jufaxexave.weebly.com
- kokexofagisukop.weebly.com
- uploads.strikinglycdn.com
- guwomenod.weebly.com
- dedotomonifagax.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report