SUSPICIOUS — normal_5f90647bb590b.pdf
SUSPICIOUS — normal_5f90647bb590b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bd1be53d663f7afcfb60062cf4524c19788898b3bf7823eec3a9eaf8d4ec9045 - SHA-1:
e5e4bfa6becf19b80ce612715047a9d751d270df - MD5:
1661a59d83b58ebdb57aa13ff5ed8c9e - ssdeep:
768:hgGzpD3p5zgJHykdd2bW5v5j3Rel1bhJLS058CJnK/rLnDdjZHtM7osMl:SGFDpA2bWzR2FVx51VKrWMsMl - TLSH:
T12C328DF710A7ECCC364B6B03AAAB105D904BD74D61369AA458C8673CC4BC5FD6E40962 - Submitted as: normal_5f90647bb590b.pdf
- File type: pdf · Size: 43938 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/68afd644-089d-41a0-ad10-2f5c14776ced/26542543442.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.cc/123?keyword=fullmetal+alchemist+imdb+parents+guide, https://zulatikuwa.weebly.com/uploads/1/3/0/7/130776211/2745832.pdf, https://sirawomaperuli.weebly.com/uploads/1/3/1/3/131398091/dasumave.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=fullmetal+alchemist+imdb+parents+guide
- https://zulatikuwa.weebly.com/uploads/1/3/0/7/130776211/2745832.pdf
- https://sirawomaperuli.weebly.com/uploads/1/3/1/3/131398091/dasumave.pdf
- https://sijevunima.weebly.com/uploads/1/3/1/8/131859613/kasatisi_vetetipedimix_pudulajelitu.pdf
- https://wirukibit.weebly.com/uploads/1/3/0/9/130969322/e13387a.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/bipidojutuguru_nofarabiwiga_poxezumasojan_lifuwageme.pdf
- https://worobewunit.weebly.com/uploads/1/3/1/4/131406731/dirisoxibodupaj.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f877570cb997.pdf
- https://cdn-cms.f-static.net/uploads/4387419/normal_5f8f85233dc75.pdf
- https://uploads.strikinglycdn.com/files/68afd644-089d-41a0-ad10-2f5c14776ced/26542543442.pdf
- https://uploads.strikinglycdn.com/files/8e4ea7ac-a4e7-4295-b031-bd9cf943e412/90528628819.pdf
- https://uploads.strikinglycdn.com/files/d7875825-80a2-4d5f-a9ad-86b808425972/gopopipexenogekizafoga.pdf
- https://s3.amazonaws.com/zuxadol/31627412123.pdf
- https://s3.amazonaws.com/pazifetanegapu/65070410478.pdf
- https://s3.amazonaws.com/subud/sonubeguromigarilifekuja.pdf
- https://cdn-cms.f-static.net/uploads/4380411/normal_5f8d8bf65f701.pdf
- https://cdn-cms.f-static.net/uploads/4388038/normal_5f8fc49430b73.pdf
- http://www.imdb.com/title/tt1355642/?ref_=nv_sr_2The
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ttraff.cc
- zulatikuwa.weebly.com
- sirawomaperuli.weebly.com
- sijevunima.weebly.com
- wirukibit.weebly.com
- jakedekokobara.weebly.com
- worobewunit.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.imdb.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report