SUSPICIOUS — normal_5f9646a93fe7e.pdf
SUSPICIOUS — normal_5f9646a93fe7e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
58a4b2ffa8d1aa238d08698e52d72bbf97d6cad9a2f82d58a390aafb8551f8db - SHA-1:
2ea94d600a527c895a3c3ae079fc3c738a18bfb9 - MD5:
4ee5ef9ae841c5663d918a6610fefe7f - ssdeep:
768:eqgGzpD9pTx+n7OiXYxEvm24INsvKgh1/5HDW86/LbGmeO3ucneWsLzguoK:0GFhpnxUmdQG1/5g/L6xeBeWsLzguoK - TLSH:
T109328CF345D7ED8C7ACB9B4369AB1169658AD3886236CB6054CC733C95BC1BCBE50820 - Submitted as: normal_5f9646a93fe7e.pdf
- File type: pdf · Size: 45706 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5e8f3e32-cb37-4b4f-98cb-bacd4286f82a/pubudozufezobofad.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.link/123?keyword=games+apps+for+android+download, https://uploads.strikinglycdn.com/files/5e8f3e32-cb37-4b4f-98cb-bacd4286f82a/pubudozufezobofad.pdf, https://uploads.strikinglycdn.com/files/efa89be2-a6d1-4d2f-b7d8-1bff6600dea5/60585427187.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=games+apps+for+android+download
- https://uploads.strikinglycdn.com/files/5e8f3e32-cb37-4b4f-98cb-bacd4286f82a/pubudozufezobofad.pdf
- https://uploads.strikinglycdn.com/files/efa89be2-a6d1-4d2f-b7d8-1bff6600dea5/60585427187.pdf
- https://uploads.strikinglycdn.com/files/56c27c4e-64b8-4460-8ccf-9641f2abd1d5/rumasujoweka.pdf
- https://uploads.strikinglycdn.com/files/458ca2d7-25bd-4402-bd02-a58e3ea5e4d2/86769973910.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/1d44b872.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/dufofugomimod.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/kuwekewugi.pdf
- https://jusujonolixutuw.weebly.com/uploads/1/3/1/3/131379247/4848509.pdf
- https://uploads.strikinglycdn.com/files/3cc25ce2-9a94-41d0-85e8-679649e08cbc/26917754946.pdf
- https://uploads.strikinglycdn.com/files/ec95dd7b-b88c-4a02-a437-b8dbccbc8731/40054186873.pdf
- https://uploads.strikinglycdn.com/files/fddaf505-fd19-485d-89eb-06453501166a/skype_picture_download.pdf
- https://uploads.strikinglycdn.com/files/db87ac30-51a7-427d-ac74-68b448477485/weporozibu.pdf
- https://uploads.strikinglycdn.com/files/6a3ee0bd-c5de-4e14-b3ef-57a1f8f3e881/bogaxonawabijo.pdf
- https://s3.amazonaws.com/memul/payment_methods_in_international_trade.pdf
- https://s3.amazonaws.com/sifawekujiki/data_structures_and_algorithms_in_java_tutorial_point.pdf
- https://s3.amazonaws.com/sasufufa/zujukutetipagixixibelufon.pdf
- https://s3.amazonaws.com/zarelusipofox/41072186073.pdf
- https://s3.amazonaws.com/vuzufexarevima/tazajerufazusa.pdf
- https://cdn.shopify.com/s/files/1/0501/0613/8787/files/43650318803.pdf
- https://cdn.shopify.com/s/files/1/0484/6678/8506/files/kiwaxisot.pdf
- https://s3.amazonaws.com/gizonukorad/vogesujikitubiziv.pdf
- https://s3.amazonaws.com/degisapemifa/40614829869.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.link
- uploads.strikinglycdn.com
- jakedekokobara.weebly.com
- saxibodusazo.weebly.com
- zafozudakajadev.weebly.com
- jusujonolixutuw.weebly.com
- s3.amazonaws.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report