SUSPICIOUS — normal_5f884fb334934.pdf
SUSPICIOUS — normal_5f884fb334934.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8e861903242553eb66a3fc40cb0653d9c1d44f3786831ad7dada0c5d4c9248f4 - SHA-1:
e1f7019a2ad4d3c1fa8293bb4fd0aee2a30f7f07 - MD5:
f82ac8fd764b408cbfc4c981b2bd7ee9 - ssdeep:
768:6gGzpD/p7ZKtz98QeMHuAtsGPaXxdybbxnVguAVRQ9wvE/haHWXs4i/x:nGF7pMt0MmdybHEVW9w8/haHWXs4i/x - TLSH:
T1C4347DF31167ED4CBACADB036DEB245C9089EB4891329B64598C776CC4BC37E6E10640 - Submitted as: normal_5f884fb334934.pdf
- File type: pdf · Size: 52661 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nipomomuka_gisotufeje.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=cm+browser+latest+version+apk+free+download, https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/d8b4f785f.pdf, https://rutaluxunenore.weebly.com/uploads/1/3/0/7/130740368/juzet.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=cm+browser+latest+version+apk+free+download
- https://besiwalufeg.weebly.com/uploads/1/3/2/6/132696214/d8b4f785f.pdf
- https://rutaluxunenore.weebly.com/uploads/1/3/0/7/130740368/juzet.pdf
- https://xumogimunosu.weebly.com/uploads/1/3/1/6/131607683/jojulibikax-bigefotigew.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nipomomuka_gisotufeje.pdf
- https://site-1036997.mozfiles.com/files/1036997/wexowep.pdf
- https://site-1042204.mozfiles.com/files/1042204/83946215378.pdf
- https://site-1039636.mozfiles.com/files/1039636/waxebusezilorinerix.pdf
- https://site-1039578.mozfiles.com/files/1039578/muparopezatamib.pdf
- https://cdn.shopify.com/s/files/1/0431/0371/5489/files/unit_4_test_congruent_triangles_answer_key_all_things_algebra.pdf
- https://cdn.shopify.com/s/files/1/0477/6201/4364/files/zilajubuvam.pdf
- https://cdn.shopify.com/s/files/1/0440/5595/3558/files/john_deere_boots_toddler.pdf
- https://cdn.shopify.com/s/files/1/0437/8945/1425/files/poperev.pdf
- https://cdn.shopify.com/s/files/1/0432/1958/3138/files/sofigatikijanogovezimoke.pdf
- https://uploads.strikinglycdn.com/files/1b1f572a-ef69-46f6-92da-2650422f7a07/70080815514.pdf
- https://uploads.strikinglycdn.com/files/3fea2d58-2daf-4bc5-a64a-82105ac1b9ea/4124492894.pdf
- https://uploads.strikinglycdn.com/files/1559624e-c44e-4114-a48f-3e094c0a9ef3/zasazalufalazogo.pdf
- https://uploads.strikinglycdn.com/files/08b28fbe-d6f6-46b7-8e76-b4308e26c842/54222717222.pdf
- https://uploads.strikinglycdn.com/files/e6970af7-7e1d-4de4-8743-15cd01950a6c/zadegajanifijavij.pdf
- https://uploads.strikinglycdn.com/files/d5835699-e4f2-4581-8a0b-d9f49635157f/84036449908.pdf
- https://uploads.strikinglycdn.com/files/de5fb25b-ca26-4330-b61c-0d1322344e1d/zilaporatigub.pdf
- https://uploads.strikinglycdn.com/files/1bc46007-7adc-4aef-953e-605661fcd4b5/50967449030.pdf
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/demajawugijudo_narasobabuson.pdf
- https://tunimesepet.weebly.com/uploads/1/3/1/4/131455680/4594d52085.pdf
Embedded domains
- cctraff.ru
- besiwalufeg.weebly.com
- rutaluxunenore.weebly.com
- xumogimunosu.weebly.com
- dutitujazekap.weebly.com
- jakedekokobara.weebly.com
- site-1036997.mozfiles.com
- site-1042204.mozfiles.com
- site-1039636.mozfiles.com
- site-1039578.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- lagukekejase.weebly.com
- tunimesepet.weebly.com
- sibakixode.weebly.com
- jiwepurojal.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report