SUSPICIOUS — normal_5f925e8b8720f.pdf
SUSPICIOUS — normal_5f925e8b8720f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5292dcd83f760721463740866461fa18dffe75bdfe150fd20012b771464b4f40 - SHA-1:
20c83666abefa219f0b2abd3607ecefacc2f0aca - MD5:
c62c2ae96e64368cbf03c911ddb5ffdc - ssdeep:
1536:JGFfpd5AvWrO1xnrMkIqKgQjZxdgSWPEG/+cr8bS:cFfpv+1xrMMQxeyyfrv - TLSH:
T149359DF351ABDC4C7ACAAB03A9BB1558558EC78D71229B9049CC7B3CC0BC6BD6E10911 - Submitted as: normal_5f925e8b8720f.pdf
- File type: pdf · Size: 61545 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/be147f17-9e38-4a1a-b7c2-1ed92c42a09b/kokumon.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.club/123?keyword=tetris+mod+apk+latest, https://cdn-cms.f-static.net/uploads/4381735/normal_5f8d57e3876b9.pdf, https://cdn-cms.f-static.net/uploads/4367920/normal_5f876f323995b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=tetris+mod+apk+latest
- https://cdn-cms.f-static.net/uploads/4381735/normal_5f8d57e3876b9.pdf
- https://cdn-cms.f-static.net/uploads/4367920/normal_5f876f323995b.pdf
- https://cdn-cms.f-static.net/uploads/4375515/normal_5f8aab4955d94.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f92385df3708.pdf
- https://s3.amazonaws.com/fibesezati/already_just_yet_ever_never_exercises.pdf
- https://s3.amazonaws.com/zirojopemup/cardiac_catheterization_procedure_steps.pdf
- https://s3.amazonaws.com/tadovu/voretejoma.pdf
- https://s3.amazonaws.com/pewibim/zokinitedolajeparo.pdf
- https://s3.amazonaws.com/xovajukoxin/85265054757.pdf
- https://s3.amazonaws.com/mubemutolewe/zudelafubanirenaja.pdf
- https://s3.amazonaws.com/felasorarabipis/godogazodaroketesur.pdf
- https://s3.amazonaws.com/xukonakefules/gloomhaven_scenario_book.pdf
- https://s3.amazonaws.com/susopuzupure/job_application_letter_file_download.pdf
- https://cdn.shopify.com/s/files/1/0432/0693/4688/files/87838856312.pdf
- https://cdn.shopify.com/s/files/1/0497/9136/9377/files/fowopuniraxo.pdf
- https://cdn.shopify.com/s/files/1/0432/2403/9592/files/3_digit_subtraction_across_zeros_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0478/0113/9359/files/83763061034.pdf
- https://cdn.shopify.com/s/files/1/0266/9009/3251/files/jaws_3_screenplay.pdf
- https://uploads.strikinglycdn.com/files/be147f17-9e38-4a1a-b7c2-1ed92c42a09b/kokumon.pdf
- https://uploads.strikinglycdn.com/files/11a2fd72-e5f9-4ff6-8402-96607b44866d/75468467070.pdf
- https://uploads.strikinglycdn.com/files/aef81f1c-a384-465b-b342-9e73d03a112f/84783757172.pdf
- https://uploads.strikinglycdn.com/files/f138a38c-8083-44a4-833f-8e0e052df761/exercicios_com_gabarito_wh_questions.pdf
- https://uploads.strikinglycdn.com/files/ac6cc066-6627-483c-962b-c69d99e6c6c4/71517423610.pdf
- https://uploads.strikinglycdn.com/files/f5fb6a35-1312-4b81-9e21-02732cab7b1b/najebikowomipurul.pdf
Embedded domains
- ttraff.club
- cdn-cms.f-static.net
- s3.amazonaws.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report