SUSPICIOUS — normal_5f8fa665d14ef.pdf
SUSPICIOUS — normal_5f8fa665d14ef.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7581f3f85a3a68a16b09ea74354cc13c93086ab5245923f9ba5950ac9ba173f1 - SHA-1:
9e7a98d4f8d59a35ca94f9df6b73d27469bce14d - MD5:
ff541f55689dc74cc2591180ae226262 - ssdeep:
768:KgGzpDppNLL+xeoiV3UP7YyFVP0pFA3v9B845Oxc2bkF5Q7tYg8QUZD+7zf1k3eR:XGFlpKSyF9D9B8haqWO7tIU7zN5R - TLSH:
T1A3318DF354ABEC0CB68B8F03A8AA15552189D789A137D750548C7B7CC5BC1BEBF00921 - Submitted as: normal_5f8fa665d14ef.pdf
- File type: pdf · Size: 43199 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/2f184948-0516-4d06-b35b-f3a9e33fc03b/63017569196.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.com/123?keyword=integers+worksheet+for+grade+6, https://cdn.shopify.com/s/files/1/0499/4246/2618/files/jufifixu.pdf, https://cdn.shopify.com/s/files/1/0268/7513/4135/files/79012877175.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ttraff.com/123?keyword=integers+worksheet+for+grade+6
- https://cdn.shopify.com/s/files/1/0499/4246/2618/files/jufifixu.pdf
- https://cdn.shopify.com/s/files/1/0268/7513/4135/files/79012877175.pdf
- https://cdn.shopify.com/s/files/1/0266/8445/7146/files/suwubaxufaduke.pdf
- https://cdn.shopify.com/s/files/1/0435/2235/9447/files/grammatik_aktiv_cornelsen_free_download.pdf
- https://cdn.shopify.com/s/files/1/0440/8098/8310/files/toshiba_dkr40ku_dvd_recorder_manual.pdf
- https://uploads.strikinglycdn.com/files/50b768bb-bb91-4283-87df-5a7164c2a40d/74529436055.pdf
- https://uploads.strikinglycdn.com/files/6ea05b84-6cbd-4440-ae9f-f2301b298bb1/dorebiba.pdf
- https://uploads.strikinglycdn.com/files/2f184948-0516-4d06-b35b-f3a9e33fc03b/63017569196.pdf
- https://uploads.strikinglycdn.com/files/49889b96-fbb3-463b-8c14-99ac7a69f932/galeze.pdf
- https://uploads.strikinglycdn.com/files/2b09ff42-5dc2-4dff-bb5e-7a507f613a50/vojokegukuju.pdf
- https://cdn-cms.f-static.net/uploads/4368496/normal_5f895752452a2.pdf
- https://cdn-cms.f-static.net/uploads/4369786/normal_5f89ebafb62bc.pdf
- https://s3.amazonaws.com/tetazino/lelibekejilixemibate.pdf
- https://s3.amazonaws.com/susopuzupure/waxutinutejopanud.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f8741a22e2a5.pdf
- https://cdn-cms.f-static.net/uploads/4379483/normal_5f8df096c014d.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/8279107.pdf
- https://xujaxivef.weebly.com/uploads/1/3/1/4/131438557/sijagaxiguzumeb.pdf
- https://jawowigo.weebly.com/uploads/1/3/0/7/130774982/9080712.pdf
- https://riragojefo.weebly.com/uploads/1/3/1/8/131857115/bomefe_dakorokitok.pdf
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/1d4e5dba7.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- fijojonibiw.weebly.com
- xujaxivef.weebly.com
- jawowigo.weebly.com
- riragojefo.weebly.com
- digonowokeke.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report