SUSPICIOUS — normal_5f8d0fe3e1125.pdf
SUSPICIOUS — normal_5f8d0fe3e1125.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6021b245f832bbe8831944ec8e26017ce30613daf7ed8716998392347387c370 - SHA-1:
a79c81215549492193192089c822209c45c2a883 - MD5:
def0408333374fd037014f5b3c58c1b3 - ssdeep:
768:ugGzpD8pb/llSkIqFIwhcCvlEzpcmXLJJSF8/61bO4ye1pIh6chD91M0fvu:LGF4pbNlSkz6weWO4yGcbM0nu - TLSH:
T124328DF350A3ED8C7A8B6F17ADA611A9958DD28D60329791448C772CC8BC6FD3E04E44 - Submitted as: normal_5f8d0fe3e1125.pdf
- File type: pdf · Size: 45902 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/712813.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.club/123?keyword=pianist+hd+piano+%252B+apk+mod, https://cdn.shopify.com/s/files/1/0500/4037/3398/files/47200950836.pdf, https://cdn.shopify.com/s/files/1/0428/5153/2963/files/a_raisin_in_the_sun.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=pianist+hd+piano+%252B+apk+mod
- https://cdn.shopify.com/s/files/1/0500/4037/3398/files/47200950836.pdf
- https://cdn.shopify.com/s/files/1/0428/5153/2963/files/a_raisin_in_the_sun.pdf
- https://cdn.shopify.com/s/files/1/0483/2647/5929/files/76526159070.pdf
- https://cdn.shopify.com/s/files/1/0480/7317/9300/files/zasixuzowajiteloferaj.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/zaralovif.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/712813.pdf
- https://uploads.strikinglycdn.com/files/7483303e-63c0-4cb6-b095-865df5fe5bcc/68265094298.pdf
- https://uploads.strikinglycdn.com/files/2e6e78d3-f7c7-45e5-bc2c-f8792f7ee4ac/18203209715.pdf
- https://uploads.strikinglycdn.com/files/6a6104d1-8b10-4451-80f9-66ea0b4aa7fb/xunobus.pdf
- https://cdn.shopify.com/s/files/1/0478/1791/6575/files/dozutabipaxumezegekawa.pdf
- https://cdn.shopify.com/s/files/1/0432/3069/1496/files/bizexojunuvo.pdf
- https://cdn.shopify.com/s/files/1/0500/9198/3013/files/bidufuvanezedivala.pdf
- https://uploads.strikinglycdn.com/files/900bfe93-1dc2-42fb-a652-0f5d927976a7/pobre_ana_characters.pdf
- https://uploads.strikinglycdn.com/files/5c5bbd6a-75b5-407e-9c7d-a67e8c05a6b5/mudosubemeguzo.pdf
- https://uploads.strikinglycdn.com/files/e12ae9f6-6030-4d55-ad84-2ab7db2dbac8/xemumepununawerofuzipaj.pdf
- https://uploads.strikinglycdn.com/files/9971993d-2f90-4af6-afb8-7fcd0453a766/59493378953.pdf
- https://uploads.strikinglycdn.com/files/0c9b2680-7580-4755-b855-548adc59dcb0/98472526642.pdf
- https://cdn-cms.f-static.net/uploads/4369776/normal_5f8b30742a4d9.pdf
- https://cdn-cms.f-static.net/uploads/4383451/normal_5f8ccdef63e41.pdf
- https://cdn-cms.f-static.net/uploads/4371248/normal_5f893af1a1b23.pdf
- https://cdn-cms.f-static.net/uploads/4367271/normal_5f8c8ecbd8633.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f8740d149eb7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.club
- cdn.shopify.com
- lagukekejase.weebly.com
- dapujevubo.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report