SUSPICIOUS — normal_5f8a90c301aab.pdf
SUSPICIOUS — normal_5f8a90c301aab.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
696055492accd7afa9a6cdc81d8714531c09d7ed253bfda74aefe8d4feaf7b50 - SHA-1:
d999b517d27732812c4a5a1e5da06ba0f0f91aea - MD5:
401b06066df2c2f79309b25f0338a73f - ssdeep:
768:jgGzpDBpkFFjolW8cMuBGzH2xe7dmcdwR9qMEhsplWeQd2plcapAZfYQ:cGFVpkFKNwfW3sLmZfYQ - TLSH:
T11B327DF710B3ED4C7BCAAB036EEB2469908AD7486132A768595C672CC4BC37D3E10950 - Submitted as: normal_5f8a90c301aab.pdf
- File type: pdf · Size: 46308 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c24446a6-7387-4545-b387-ae3d1da8714c/47417174553.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.club/123?keyword=trends+in+cognitive+sciences+author+instructions, https://uploads.strikinglycdn.com/files/c24446a6-7387-4545-b387-ae3d1da8714c/47417174553.pdf, https://uploads.strikinglycdn.com/files/f81aec34-bac5-491e-b4b4-7de4aaa9f777/gudesefapikamuwuperenali.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=trends+in+cognitive+sciences+author+instructions
- https://uploads.strikinglycdn.com/files/c24446a6-7387-4545-b387-ae3d1da8714c/47417174553.pdf
- https://uploads.strikinglycdn.com/files/f81aec34-bac5-491e-b4b4-7de4aaa9f777/gudesefapikamuwuperenali.pdf
- https://uploads.strikinglycdn.com/files/27638196-bffa-4cb6-bf5e-d58930e8c367/mumej.pdf
- https://cdn.shopify.com/s/files/1/0481/6807/5413/files/biology_for_dummies.pdf
- https://cdn.shopify.com/s/files/1/0434/2687/3509/files/buginijutu.pdf
- https://cdn.shopify.com/s/files/1/0468/1151/2986/files/45578976057.pdf
- https://cdn.shopify.com/s/files/1/0476/7481/8726/files/hypersonic_glide_vehicle.pdf
- https://cdn.shopify.com/s/files/1/0495/9744/8355/files/dodarerilobenumawenivedo.pdf
- https://cdn.shopify.com/s/files/1/0266/8340/8571/files/96447499219.pdf
- https://cdn.shopify.com/s/files/1/0486/5707/2296/files/sd_card_format_pro_apk.pdf
- https://cdn.shopify.com/s/files/1/0433/8515/9843/files/wudew.pdf
- https://cdn.shopify.com/s/files/1/0482/4622/7096/files/wojobe.pdf
- https://cdn.shopify.com/s/files/1/0438/2959/2214/files/add_1st_edition.pdf
- https://uploads.strikinglycdn.com/files/2c538a33-6cc5-4d68-8ade-635c0e0fdadd/computer_friert_ein_wenn_Links_im_L.pdf
- https://uploads.strikinglycdn.com/files/2bf93ef2-1c6f-4969-b2bd-7b1a6d25f062/zifovapozixegowafa.pdf
- https://uploads.strikinglycdn.com/files/ca20e162-d104-4bb0-a014-5d7d712fd1e6/52521753786.pdf
- https://uploads.strikinglycdn.com/files/6affd511-9708-4952-b3b0-2347d5a127b2/fajumipowotugejesowiva.pdf
- https://uploads.strikinglycdn.com/files/ea3cb59c-b661-4376-bbaa-af316ddcfba6/43804110854.pdf
- https://uploads.strikinglycdn.com/files/d2d43f45-0fd1-4f77-92ff-3f37b15e9958/luwinevenosumofetojosux.pdf
- https://uploads.strikinglycdn.com/files/6d3cfe78-293b-4bae-99c3-c9cc176a68ae/73934388530.pdf
- https://cdn-cms.f-static.net/uploads/4371787/normal_5f88b1634afa1.pdf
- https://cdn-cms.f-static.net/uploads/4375894/normal_5f89d38b9f68f.pdf
- https://cdn-cms.f-static.net/uploads/4377663/normal_5f8a51ac548a0.pdf
- https://cdn-cms.f-static.net/uploads/4366325/normal_5f875b1779411.pdf
Embedded domains
- ttraff.club
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report