SUSPICIOUS — normal_5f93a9fd85ac2.pdf
SUSPICIOUS — normal_5f93a9fd85ac2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
952ee97d0569a6f1b0db1808be3e0b70136ed4f0a2b492c99337126177ed2292 - SHA-1:
2e7ab7e3a97770eecda561354356a98c5b394563 - MD5:
8862b648da017782c35fcd063521e774 - ssdeep:
768:3gGzpDRjGqTdIjNV3nDOFaMN5vK/ajXqw6HEhtGunQW/PySu2gnCywL7iyJ:QGFNjvK/r9kSunQW/Ppu2oCys7iyJ - TLSH:
T157338DF340A7ED8C3A87A78369BB5559554AC78C323397A05A8C7B2CC1BC67DAF00950 - Submitted as: normal_5f93a9fd85ac2.pdf
- File type: pdf · Size: 48422 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/12d2569d-f5c1-4b18-9945-aabb6579372c/32737514319.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.link/123?keyword=generalidades+sobre+la+corteza+cerebral+pdf, https://cdn-cms.f-static.net/uploads/4377400/normal_5f8aa30de5fe3.pdf, https://cdn-cms.f-static.net/uploads/4369324/normal_5f88175b78ab7.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.link/123?keyword=generalidades+sobre+la+corteza+cerebral+pdf
- https://cdn-cms.f-static.net/uploads/4377400/normal_5f8aa30de5fe3.pdf
- https://cdn-cms.f-static.net/uploads/4369324/normal_5f88175b78ab7.pdf
- https://cdn-cms.f-static.net/uploads/4369503/normal_5f8be43f5522b.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f8773af96e6b.pdf
- https://cdn.shopify.com/s/files/1/0497/7888/4759/files/step_pedometer_android_app.pdf
- https://cdn.shopify.com/s/files/1/0438/8831/2488/files/interprovincial_red_seal_examination_preparation_information_guide.pdf
- https://cdn.shopify.com/s/files/1/0486/0441/4120/files/barangay_174_camarin_caloocan_city_zip_code.pdf
- https://uploads.strikinglycdn.com/files/12d2569d-f5c1-4b18-9945-aabb6579372c/32737514319.pdf
- https://uploads.strikinglycdn.com/files/fb28cb84-8bc9-47dd-9b8c-4068e2366a81/37024112815.pdf
- https://cdn.shopify.com/s/files/1/0431/2721/0144/files/vofudolutuxiledur.pdf
- https://cdn.shopify.com/s/files/1/0438/9981/4040/files/25313980732.pdf
- https://cdn.shopify.com/s/files/1/0268/7431/4946/files/tofijewezuguvukozixe.pdf
- https://uploads.strikinglycdn.com/files/c3e1beb7-ba06-448a-827f-efe8167c9674/67704041065.pdf
- https://uploads.strikinglycdn.com/files/ef69428b-97d5-45ce-9b9c-2474d86ac246/39324261548.pdf
- https://uploads.strikinglycdn.com/files/43bc8e11-d9fa-4d1e-98dc-5369b84b7d41/fisubekojeletonamo.pdf
- https://uploads.strikinglycdn.com/files/e0e7e52a-0dae-4d00-b5f3-e8294e3361c9/30440946707.pdf
- https://uploads.strikinglycdn.com/files/69422430-2588-4336-8aec-f6bf0dbbc83b/blood_orange_angels_pulse_rar_download.pdf
- https://cdn.shopify.com/s/files/1/0491/8103/2614/files/kuhner_shaker_incubator_manual.pdf
- https://cdn.shopify.com/s/files/1/0430/5515/3303/files/android_scaletype_for_background.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ttraff.link
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report