SUSPICIOUS — normal_5f91d8ae34a1e.pdf
SUSPICIOUS — normal_5f91d8ae34a1e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9b34fd894c3d5bcddb563ee7ed57dd83da82934f3c2059e29e6ce3ec2674a72c - SHA-1:
c78d6db26f17dc05ceba9452a1d49e571c2f965b - MD5:
f64b633ed41e91bdb0636d26092135e8 - ssdeep:
768:ogGzpDHeyGmYSKyKcsWGaqZqIZ7lX62QGQr4wP4SF43Y/VtbA7wqUjIk2xVeK3U/:lGFze42cOqDwSF4ottM7w32b5a3hF - TLSH:
T17334BFF31097DD8C7A8B6B07A9E6025C904ED78D6132D75015C87B2CC5BCAFEAE10A61 - Submitted as: normal_5f91d8ae34a1e.pdf
- File type: pdf · Size: 57179 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/93cd16e3-3cb8-4f62-bbcf-ca54f1ab3781/chin_no_ma_kia_tp_6.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.me/123?keyword=must+read+book+list+pdf, https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/9706758.pdf, https://segakimorepej.weebly.com/uploads/1/3/0/7/130738797/8268263.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=must+read+book+list+pdf
- https://nipufijupetobug.weebly.com/uploads/1/3/1/4/131482996/9706758.pdf
- https://segakimorepej.weebly.com/uploads/1/3/0/7/130738797/8268263.pdf
- https://sirawomaperuli.weebly.com/uploads/1/3/1/3/131398091/b893a7593d8e.pdf
- https://xexovelez.weebly.com/uploads/1/3/0/8/130813416/ef43264355.pdf
- https://uploads.strikinglycdn.com/files/93cd16e3-3cb8-4f62-bbcf-ca54f1ab3781/chin_no_ma_kia_tp_6.pdf
- https://nukevokisoget.weebly.com/uploads/1/3/2/7/132711970/peval-kamerip.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/wotitir.pdf
- https://kuzaloxamuw.weebly.com/uploads/1/3/1/4/131406684/8411480.pdf
- https://uploads.strikinglycdn.com/files/a6675de4-6dc4-4bf5-8416-02173477dec4/jalebebejimapan.pdf
- https://uploads.strikinglycdn.com/files/f8403526-21e7-48dc-98fa-72d1e3691a4c/80920993234.pdf
- https://uploads.strikinglycdn.com/files/cd266084-e022-458f-a620-f759aa2c70f9/bakuvazodibikipa.pdf
- https://uploads.strikinglycdn.com/files/10ec5ce1-0758-4e84-9c2d-4f5e9f73690d/kokiduxexilab.pdf
- https://uploads.strikinglycdn.com/files/8e9cd6c5-51c8-48ce-8451-0ad7f48a46de/lakolasixijegalonudosomet.pdf
- https://cdn.shopify.com/s/files/1/0482/7643/9198/files/multiple_sql_statements_in_one_query_c.pdf
- https://cdn.shopify.com/s/files/1/0266/8445/7140/files/assignment_cover_page_format.pdf
- https://cdn.shopify.com/s/files/1/0501/9664/4016/files/android_sdk_tools_for_unity.pdf
- https://cdn.shopify.com/s/files/1/0499/3499/1528/files/lego_robot_arm.pdf
- https://cdn.shopify.com/s/files/1/0488/0685/4821/files/music_download_programs_for_android.pdf
- https://cdn.shopify.com/s/files/1/0432/3137/9619/files/7082811888.pdf
- https://cdn.shopify.com/s/files/1/0484/9431/3627/files/31_usc_1501.pdf
- https://cdn.shopify.com/s/files/1/0501/8304/5293/files/honeywell_5808w3_wireless_smoke_detector_manual.pdf
- https://cdn.shopify.com/s/files/1/0504/2064/6048/files/buzovuwewusevokad.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.me
- nipufijupetobug.weebly.com
- segakimorepej.weebly.com
- sirawomaperuli.weebly.com
- xexovelez.weebly.com
- uploads.strikinglycdn.com
- nukevokisoget.weebly.com
- walijogopabo.weebly.com
- kuzaloxamuw.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report