SUSPICIOUS — normal_5f96a257d85f7.pdf
SUSPICIOUS — normal_5f96a257d85f7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6cbdc298c865a8b99d1ed786466e8acd080929c42a7a3a0382fe791dadb3b106 - SHA-1:
83f2ea93f6dfc982987929489999c06fead6972a - MD5:
3aead71fefd928cfc7663716cafa7ce8 - ssdeep:
768:MgGzpDFpZh8izKmb8qBTHV4lxwy/WBKOfUmjkFXdXSGh4P7IKA2aDphzor:JGFRpFY3/W0OhjG8Gg7L8rUr - TLSH:
T151329FF35097FC8C7B8A9B4399AB2199A149D38D7136D660258C2B2CD47C6FD3E00662 - Submitted as: normal_5f96a257d85f7.pdf
- File type: pdf · Size: 44379 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ecba46a1-4a88-4e6a-a4d9-6f69662409df/diziw.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.ru/123?keyword=total+war+shogun+2+units+guide, https://uploads.strikinglycdn.com/files/ecba46a1-4a88-4e6a-a4d9-6f69662409df/diziw.pdf, https://uploads.strikinglycdn.com/files/061a4fe8-2f6f-4ece-a617-75648809a369/41553201879.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=total+war+shogun+2+units+guide
- https://uploads.strikinglycdn.com/files/ecba46a1-4a88-4e6a-a4d9-6f69662409df/diziw.pdf
- https://uploads.strikinglycdn.com/files/061a4fe8-2f6f-4ece-a617-75648809a369/41553201879.pdf
- https://uploads.strikinglycdn.com/files/fa332328-ff8b-4e79-b2f2-fcf35180f713/latigupalorupenoru.pdf
- https://uploads.strikinglycdn.com/files/485b5ecd-5771-4927-b8fb-4962b3d83b6d/konosuba_volume_11.pdf
- https://cdn-cms.f-static.net/uploads/4391319/normal_5f9297b6b3853.pdf
- https://cdn-cms.f-static.net/uploads/4367646/normal_5f881ff92f710.pdf
- https://cdn.shopify.com/s/files/1/0486/3456/0670/files/jung_seung_yeon_birthday.pdf
- https://cdn.shopify.com/s/files/1/0495/6133/8012/files/74324613349.pdf
- https://cdn.shopify.com/s/files/1/0483/8332/8405/files/41518132647.pdf
- https://cdn.shopify.com/s/files/1/0500/5328/4008/files/farming_simulator_18_revdl_com_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0501/5925/5717/files/80783043684.pdf
- https://fekoguto.weebly.com/uploads/1/3/4/4/134491689/rimegafimiwot.pdf
- https://rogidalot.weebly.com/uploads/1/3/1/6/131636841/baxorixofajedu.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/caa64.pdf
- https://viwuwobigoku.weebly.com/uploads/1/3/1/3/131378942/tefidasixenabi.pdf
- https://cdn.shopify.com/s/files/1/0478/1791/6575/files/97345522290.pdf
- https://cdn.shopify.com/s/files/1/0498/1404/4827/files/cow_hitch_knot_paracord.pdf
- https://cdn.shopify.com/s/files/1/0498/8675/7018/files/zulunizojasoxidopi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- fekoguto.weebly.com
- rogidalot.weebly.com
- dimaxafazeza.weebly.com
- viwuwobigoku.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report