SUSPICIOUS — the_dumbest_generation.pdf
SUSPICIOUS — the_dumbest_generation.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7dc7c5773d0945a823e57c6cf9d99059cd0b3e3f79d09f27823494b38cf91e1f - SHA-1:
1881739277dc0802589d8eb6e7f973c12f421a72 - MD5:
cda1d6ae855ad8f33ec5f54ed6c6c2d3 - ssdeep:
768:SgGzpDVprHcFD6rhnbLdRKwBnV9VCS9Qvs2mB/NxLTcJ1w9liT/+CD:PGFhpLrhbLlz9Q1vslB/vo1w9lw+CD - TLSH:
T1C2339EF31097EC8C7AC6AB03ADF62555618ADB483236EBA0548C376DC4BC6BD7E00951 - Submitted as: the_dumbest_generation.pdf
- File type: pdf · Size: 49025 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f72e8d7a-e3ce-416a-8363-58ce2fa92d93/49611590627.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=the+dumbest+generation+pdf, https://cdn.shopify.com/s/files/1/0501/6875/8453/files/3145498854.pdf, https://cdn.shopify.com/s/files/1/0501/6354/8325/files/53911044208.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=the+dumbest+generation+pdf
- https://cdn.shopify.com/s/files/1/0501/6875/8453/files/3145498854.pdf
- https://cdn.shopify.com/s/files/1/0501/6354/8325/files/53911044208.pdf
- https://cdn.shopify.com/s/files/1/0502/4789/3192/files/87563047297.pdf
- https://s3.amazonaws.com/tadovu/mozepewobirumoseteruvese.pdf
- https://s3.amazonaws.com/henghuili-files/pdf_to_word_ocr_software.pdf
- https://s3.amazonaws.com/wujapu/16438097564.pdf
- https://gukaguse.weebly.com/uploads/1/3/1/3/131398473/suwererixok.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/mezaguwok.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/124b884337150.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/819ac2f13.pdf
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/e2743e766db5618.pdf
- https://bilewazivabo.weebly.com/uploads/1/3/2/8/132816117/7268132.pdf
- https://uploads.strikinglycdn.com/files/f72e8d7a-e3ce-416a-8363-58ce2fa92d93/49611590627.pdf
- https://uploads.strikinglycdn.com/files/dfa2fdfc-3e1f-4a34-999d-86adfa84659b/subezarudubivavi.pdf
- https://uploads.strikinglycdn.com/files/5b5c477f-b8f3-41de-82e9-0a81d9858cf4/nudag.pdf
- https://uploads.strikinglycdn.com/files/ab7a36ca-23d0-44f0-b936-fe54dfd34366/kilabusizafi.pdf
- https://uploads.strikinglycdn.com/files/adaf5018-372e-437a-bbae-62cbf15dda84/raxutuzarujutoro.pdf
- https://uploads.strikinglycdn.com/files/2cdf7034-738c-4262-a5d7-7bbeb986fc5c/fugokojevof.pdf
- https://uploads.strikinglycdn.com/files/4852810f-027c-4fe8-9890-bdb41827fe75/wularigeb.pdf
- https://uploads.strikinglycdn.com/files/cf2f1cb5-02d4-4819-91ed-1e933aff798b/dragon_ball_z_complete_series_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- s3.amazonaws.com
- gukaguse.weebly.com
- tivakoxidedopa.weebly.com
- taxajadotediru.weebly.com
- netaluzubik.weebly.com
- wetuxabo.weebly.com
- bilewazivabo.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report