SUSPICIOUS — comptia_security_deluxe_study_guide_exam_sy0-501.pdf
SUSPICIOUS — comptia_security_deluxe_study_guide_exam_sy0-501.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e0c27146f1480b2b77cfef7c2b0be100919f5c2f8546f09a4d98518979ccb913 - SHA-1:
8f725f487e22cd54ccfee47bc53922c2d601e6eb - MD5:
bfca2e49099a2931ff1554ed7f0e2415 - ssdeep:
768:QgGzpDCpRfLMpeciReSevmXWuJYsEh/HxW4kGlV8Ikdlatz/oIFZwfdhTzezb3:9GFepgcWuCVH04kGl8Mt/oIFZeTyzb3 - TLSH:
T1E434BFF304DBED4C7E8A5B53ADE711A5648EC7897136A7A008CC6B2CC57C2BD6E01920 - Submitted as: comptia_security_deluxe_study_guide_exam_sy0-501.pdf
- File type: pdf · Size: 52457 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4365998/normal_5f8709fb687ed.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=comptia+security++deluxe+study+guide+exam+sy0-501+pdf, https://cdn-cms.f-static.net/uploads/4366984/normal_5f8737c12f42a.pdf, https://cdn-cms.f-static.net/uploads/4379032/normal_5f8ce93569db2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=comptia+security++deluxe+study+guide+exam+sy0-501+pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f8737c12f42a.pdf
- https://cdn-cms.f-static.net/uploads/4379032/normal_5f8ce93569db2.pdf
- https://cdn-cms.f-static.net/uploads/4376099/normal_5f8b74b508784.pdf
- https://cdn-cms.f-static.net/uploads/4370737/normal_5f8a31de21f01.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f8709fb687ed.pdf
- https://cdn-cms.f-static.net/uploads/4374520/normal_5f88f9c53fcab.pdf
- https://cdn-cms.f-static.net/uploads/4380080/normal_5f8cb9a82cda7.pdf
- https://cdn-cms.f-static.net/uploads/4377912/normal_5f8a7eeeec434.pdf
- https://cdn-cms.f-static.net/uploads/4366331/normal_5f87642f417a9.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/bolitixikoxabove.pdf
- https://zukamukenipebo.weebly.com/uploads/1/3/1/3/131380388/gedizavetokuzir_resorube_jizikamokatuwe_tonad.pdf
- https://tipefejiri.weebly.com/uploads/1/3/0/9/130969755/5ed737b.pdf
- https://derodaju.weebly.com/uploads/1/3/1/6/131606282/nufonaruto_zavowefi_lirosedipatixes.pdf
- https://gewosawoma.weebly.com/uploads/1/3/0/7/130739201/rofefovitijajen-sebarirakolexa.pdf
- https://kiseridebajesa.weebly.com/uploads/1/3/1/4/131408791/tupitabuxu.pdf
- https://penulikadima.weebly.com/uploads/1/3/1/4/131482887/2168795.pdf
- https://natizupasa.weebly.com/uploads/1/3/1/4/131437725/nobidejaguwivawo.pdf
- https://cdn.shopify.com/s/files/1/0435/0240/3750/files/vazum.pdf
- https://cdn.shopify.com/s/files/1/0432/4891/0498/files/47015242294.pdf
- https://zizuralozirufu.weebly.com/uploads/1/3/1/4/131483034/258d59bfeca.pdf
- https://lejigatoni.weebly.com/uploads/1/3/1/8/131871980/lenasoritevegijalaf.pdf
- https://dubuzosokiboxof.weebly.com/uploads/1/3/1/1/131163723/1867998.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- rabifupokuwu.weebly.com
- zukamukenipebo.weebly.com
- tipefejiri.weebly.com
- derodaju.weebly.com
- gewosawoma.weebly.com
- kiseridebajesa.weebly.com
- penulikadima.weebly.com
- natizupasa.weebly.com
- cdn.shopify.com
- zizuralozirufu.weebly.com
- lejigatoni.weebly.com
- dubuzosokiboxof.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report