SUSPICIOUS — normal_5f8bbd0cb6220.pdf
SUSPICIOUS — normal_5f8bbd0cb6220.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a8fa36cff75a892a4092ce297e3de56860111305e520c8e6205df4650e54f2ac - SHA-1:
e29fb63dfd9b20f21107ea47116dc5df85ab8624 - MD5:
5558a8b3524413e789c964f754b539ac - ssdeep:
768:2gGzpDFpefcLJb8xA2+J6FyZ4wWsJqFa81zWUc1clab1Z0nAdv1c6sKAioWwkJF:jGFppoub8xF+BEYRM2vK7swkJF - TLSH:
T199338DF320E7ED4CBA8B6B136EB60199654FD7886027A791458C372CC4BCAFD6E11610 - Submitted as: normal_5f8bbd0cb6220.pdf
- File type: pdf · Size: 49860 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a3eb4ddb-6bfb-45c2-ab9f-8a8b3f47cfc8/74721129002.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.com/123?keyword=barnett+game+crusher+3.0+manual, https://cdn-cms.f-static.net/uploads/4370054/normal_5f88471ab0a44.pdf, https://cdn-cms.f-static.net/uploads/4368748/normal_5f8aedc2e89da.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.com/123?keyword=barnett+game+crusher+3.0+manual
- https://cdn-cms.f-static.net/uploads/4370054/normal_5f88471ab0a44.pdf
- https://cdn-cms.f-static.net/uploads/4368748/normal_5f8aedc2e89da.pdf
- https://cdn-cms.f-static.net/uploads/4377116/normal_5f8a7a088b0ad.pdf
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f89ecd7363a8.pdf
- https://cdn-cms.f-static.net/uploads/4377924/normal_5f8aca588876b.pdf
- https://uploads.strikinglycdn.com/files/a3eb4ddb-6bfb-45c2-ab9f-8a8b3f47cfc8/74721129002.pdf
- https://uploads.strikinglycdn.com/files/181e9eb0-701d-46b9-af21-b99f63dc1d74/raviwetalom.pdf
- https://uploads.strikinglycdn.com/files/642c6ad4-0a89-4229-b6a3-19a84a06645d/91547020597.pdf
- https://uploads.strikinglycdn.com/files/2cce2500-40f3-49d4-91cd-30a14c1e13e9/wejuzurotimoniseg.pdf
- https://uploads.strikinglycdn.com/files/53ee7da0-9030-4af8-9d09-6f574849d13f/kagewizikunodapobimojinej.pdf
- https://digafixi.weebly.com/uploads/1/3/0/7/130776371/a0d7209b96ca.pdf
- https://namunobuwuper.weebly.com/uploads/1/3/0/7/130776476/donepogoruxo-bizaj-kigim-xunap.pdf
- https://cdn-cms.f-static.net/uploads/4368760/normal_5f8b6aa8b081d.pdf
- https://cdn-cms.f-static.net/uploads/4372358/normal_5f89f85430abb.pdf
- https://cdn-cms.f-static.net/uploads/4366958/normal_5f8767295d69e.pdf
- https://cdn-cms.f-static.net/uploads/4375356/normal_5f8ba83fdfba5.pdf
- https://cdn-cms.f-static.net/uploads/4375890/normal_5f8a7184165b2.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5f88c2c858784.pdf
- https://cdn-cms.f-static.net/uploads/4370054/normal_5f8943f139330.pdf
- https://uploads.strikinglycdn.com/files/3576b1f6-dc7c-4f1a-9781-325d67137d57/risoluzexenuromotew.pdf
- https://uploads.strikinglycdn.com/files/94ac0605-7f52-4779-bddd-70715282d66d/pifaw.pdf
- https://uploads.strikinglycdn.com/files/3881555f-1ada-4049-a8d7-52d64657e68a/17365750740.pdf
- https://uploads.strikinglycdn.com/files/96c46be9-a55a-4f17-9c3f-ff584c18ce67/tuzexipa.pdf
- https://uploads.strikinglycdn.com/files/84a16012-1f11-469b-b2cc-f0d5b2c4b674/94989837886.pdf
Embedded domains
- ttraff.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- digafixi.weebly.com
- namunobuwuper.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report