SUSPICIOUS — normal_5f8fe1d267432.pdf
SUSPICIOUS — normal_5f8fe1d267432.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
891c513502509fc66f5314602d2f6df3f662c78a0a4241d426591143b4b85dd7 - SHA-1:
595b407353b3d532b56754419453131fb05b9bd8 - MD5:
40b889f750c5cd0bcbc54e76f05ec7a6 - ssdeep:
768:UgGzpDip5d1/WOBS36rmlU/RZMEcDjGAEhTNuw6j6THRnOUAKtfAhLZhQdTW/sQq:hGFGpJcPQlNuw6ggUZhTWfGbFxVQ8 - TLSH:
T14033AEF314DBED8C6AC79F83ADE62159644AC74D312697600998763CC4BCA7DBF00861 - Submitted as: normal_5f8fe1d267432.pdf
- File type: pdf · Size: 52256 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4fbf2caa-4cb3-4b10-a980-d1ab96d51d44/28018624967.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.club/123?keyword=ranking+test+reasoning+questions+pdf, https://cdn.shopify.com/s/files/1/0505/8582/9541/files/recover_deleted_videos_from_sd_card_apk.pdf, https://cdn.shopify.com/s/files/1/0492/8028/6876/files/kivofuxapopifowof.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=ranking+test+reasoning+questions+pdf
- https://cdn.shopify.com/s/files/1/0505/8582/9541/files/recover_deleted_videos_from_sd_card_apk.pdf
- https://cdn.shopify.com/s/files/1/0492/8028/6876/files/kivofuxapopifowof.pdf
- https://cdn.shopify.com/s/files/1/0493/6138/7676/files/32404138366.pdf
- https://cdn.shopify.com/s/files/1/0435/0525/4566/files/google_photos_duplicate_video.pdf
- https://cdn.shopify.com/s/files/1/0434/0101/9548/files/nba_basketball_playbook.pdf
- https://uploads.strikinglycdn.com/files/4fbf2caa-4cb3-4b10-a980-d1ab96d51d44/28018624967.pdf
- https://uploads.strikinglycdn.com/files/95c70275-e0f2-4638-b7a9-eddc0fdc547d/27436727520.pdf
- https://uploads.strikinglycdn.com/files/3e773594-5a4d-4665-8097-7df203affcc2/wolizimosaguwavar.pdf
- https://uploads.strikinglycdn.com/files/29c86f42-bc39-4534-9781-642b91468af8/ley_de_coulomb_problemas.pdf
- https://cdn-cms.f-static.net/uploads/4369152/normal_5f8a5e2bda22d.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f870d05c5183.pdf
- https://cdn-cms.f-static.net/uploads/4368748/normal_5f8db964da3eb.pdf
- https://cdn-cms.f-static.net/uploads/4369508/normal_5f885449eaecf.pdf
- https://cdn-cms.f-static.net/uploads/4382614/normal_5f8b7a9d8913e.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/7348375.pdf
- https://nipaxibovaj.weebly.com/uploads/1/3/1/3/131379211/5e616607ed.pdf
- https://wefolukozik.weebly.com/uploads/1/3/1/4/131406413/ba1c8.pdf
- https://cdn.shopify.com/s/files/1/0497/3114/1783/files/66834512840.pdf
- https://cdn.shopify.com/s/files/1/0427/6381/3020/files/3509232093.pdf
- https://vewutaniwem.weebly.com/uploads/1/3/0/8/130873717/3590787.pdf
- https://saxexowiki.weebly.com/uploads/1/3/0/9/130969873/4deb66db41.pdf
- https://wajiresejepo.weebly.com/uploads/1/3/0/7/130774962/bobeduj.pdf
- https://firerokuk.weebly.com/uploads/1/3/1/1/131164187/4198302.pdf
- https://nidixinaxob.weebly.com/uploads/1/3/0/7/130739699/9105116.pdf
Embedded domains
- ttraff.club
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- rabifupokuwu.weebly.com
- nipaxibovaj.weebly.com
- wefolukozik.weebly.com
- vewutaniwem.weebly.com
- saxexowiki.weebly.com
- wajiresejepo.weebly.com
- firerokuk.weebly.com
- nidixinaxob.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report