SUSPICIOUS — normal_5f9678bf2f403.pdf
SUSPICIOUS — normal_5f9678bf2f403.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b958bb049552fd59fe841ca6058ffc60beb726454b813bb4858c2dbeca65c008 - SHA-1:
48a53b7dde938be2fa43e08016a2689a33b668e0 - MD5:
a9e8cad0f289183df9b8c7c5f09ec221 - ssdeep:
768:+gGzpDypBlbq2NPgbb3S40M1b3uyO1Bac/JvCaMtVwSiGuoUs:7GF+pBQVyJCaMIhoUs - TLSH:
T1DC317CF31497ED8CBA87DB03ADEB1069958DC3886137A7604688672DC0FC7ADBE10911 - Submitted as: normal_5f9678bf2f403.pdf
- File type: pdf · Size: 40516 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/8e0b802e-bdc3-4281-ac6b-e6b891699b2d/battletech_heavy_metal_plus.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.club/123?keyword=convert+word+to+pdf+small+pdf, https://cdn.shopify.com/s/files/1/0429/3633/6540/files/vodajezugefuwizi.pdf, https://cdn.shopify.com/s/files/1/0497/7934/3527/files/polyatomic_ions_pogil_answer_key.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=convert+word+to+pdf+small+pdf
- https://cdn.shopify.com/s/files/1/0429/3633/6540/files/vodajezugefuwizi.pdf
- https://cdn.shopify.com/s/files/1/0497/7934/3527/files/polyatomic_ions_pogil_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0502/4920/3885/files/king_dedede_combo_guide.pdf
- https://netaluzubik.weebly.com/uploads/1/3/0/8/130813777/420f5f7a589e.pdf
- https://bubixoduxufito.weebly.com/uploads/1/3/1/0/131070588/gowaw.pdf
- https://risimapi.weebly.com/uploads/1/3/4/3/134321435/nexotirarido_madapovota_kisini.pdf
- https://sowosevutab.weebly.com/uploads/1/3/4/3/134311467/7d53e5a70a8.pdf
- https://fidurelofomus.weebly.com/uploads/1/3/0/7/130740547/xenutisavobokujesi.pdf
- https://uploads.strikinglycdn.com/files/8e0b802e-bdc3-4281-ac6b-e6b891699b2d/battletech_heavy_metal_plus.pdf
- https://uploads.strikinglycdn.com/files/a778f59f-5c51-4886-9868-2a950e4fb65a/41666136842.pdf
- https://uploads.strikinglycdn.com/files/b71a2a51-f33f-45ab-b605-e38e28dc081f/wicca_guide_for_the_solitary_practitioner.pdf
- https://uploads.strikinglycdn.com/files/7f4da6f7-57ad-4e7b-8997-ce2baf0ac990/47408640982.pdf
- https://uploads.strikinglycdn.com/files/7aef19d1-ab9d-4adb-aba6-d3e86cc803bc/setozuwufidivut.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f87163a5f152.pdf
- https://cdn-cms.f-static.net/uploads/4375200/normal_5f8aac829ea42.pdf
- https://cdn-cms.f-static.net/uploads/4379240/normal_5f92e5eebf08b.pdf
- https://cdn-cms.f-static.net/uploads/4367920/normal_5f88a97f8957d.pdf
- https://cdn.shopify.com/s/files/1/0484/2451/7790/files/upstream_advanced_c1_students_book_download.pdf
- https://cdn.shopify.com/s/files/1/0463/1052/3045/files/93258676439.pdf
- https://uploads.strikinglycdn.com/files/31eeff37-953c-4484-8a85-b5ec710556cd/nefadilolofanidijog.pdf
- https://uploads.strikinglycdn.com/files/53bcc9e4-42ec-43d6-9d89-51bb6eb70e55/residencia_militar_valencia_fotos.pdf
- https://uploads.strikinglycdn.com/files/0bddd982-c1dd-41b6-ac98-b14be34e0f26/guia_de_santillana_4_grado.pdf
- https://uploads.strikinglycdn.com/files/fa2bbfc2-718a-45d6-8e97-1b68a93d3fda/zafikunavujarove.pdf
- https://uploads.strikinglycdn.com/files/52fa0fb2-58eb-436d-bc38-89527a67bcd9/75536828310.pdf
Embedded domains
- ttraff.club
- cdn.shopify.com
- netaluzubik.weebly.com
- bubixoduxufito.weebly.com
- risimapi.weebly.com
- sowosevutab.weebly.com
- fidurelofomus.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report