SUSPICIOUS — normal_5f89970bab396.pdf
SUSPICIOUS — normal_5f89970bab396.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e11146db56a09f411357b1894375ef05b9f5350c6db0ea7d1662a5f6796e4a77 - SHA-1:
75086535d3526c858453794e737a84b6fd8ec3d5 - MD5:
c4b5288370f748b2e5b81e96b2a7571f - ssdeep:
768:JggGzpDrp/cRe4t8oZeDmqff9VRV4l5g4Ld8sJy9izEg3WnD7E7UUbeu:jGFvpdxff9ql5gYd8+DEwy7E4Nu - TLSH:
T189319DF754ABED4C7A86AB03ADFB215941CDC24C6176D360458C672CE0BC6BE7E108A1 - Submitted as: normal_5f89970bab396.pdf
- File type: pdf · Size: 42951 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/98c54f69-5145-43bb-b61f-460e85e8307e/39828157773.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.club/123?keyword=serializable+object+in+android, https://uploads.strikinglycdn.com/files/ac46423c-fa41-4143-8004-a36e1505ea22/zifujosewav.pdf, https://uploads.strikinglycdn.com/files/9800c23f-95ce-42e7-b921-6b6f810044a3/63961760814.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.club/123?keyword=serializable+object+in+android
- https://uploads.strikinglycdn.com/files/ac46423c-fa41-4143-8004-a36e1505ea22/zifujosewav.pdf
- https://uploads.strikinglycdn.com/files/9800c23f-95ce-42e7-b921-6b6f810044a3/63961760814.pdf
- https://uploads.strikinglycdn.com/files/6afcf7db-4b3e-49ab-8580-fcd17505ef6e/mobubajuwapufa.pdf
- https://uploads.strikinglycdn.com/files/2821a4f6-ca84-4692-8952-f95c557681cb/togugalu.pdf
- https://cdn.shopify.com/s/files/1/0493/4293/9290/files/53562401468.pdf
- https://cdn.shopify.com/s/files/1/0266/8514/5272/files/watch_skam_online.pdf
- https://cdn.shopify.com/s/files/1/0479/2113/5783/files/86914060813.pdf
- https://cdn.shopify.com/s/files/1/0499/2018/0376/files/starbucks_swot_analysis.pdf
- https://uploads.strikinglycdn.com/files/98c54f69-5145-43bb-b61f-460e85e8307e/39828157773.pdf
- https://uploads.strikinglycdn.com/files/7403c63e-816c-440a-806c-2d0fe6bad8ae/18352307014.pdf
- https://uploads.strikinglycdn.com/files/7dec187f-b45f-4c58-a374-d11039536ba5/33759151215.pdf
- https://uploads.strikinglycdn.com/files/fefe6642-6872-40f5-be65-04a962f92fa1/39877801078.pdf
- https://uploads.strikinglycdn.com/files/badbfecf-1594-44c8-8f53-503de4437c64/fixulemisemuvemawoduk.pdf
- https://uploads.strikinglycdn.com/files/b6fb4d92-2b00-4522-8cf4-68ed5accf859/93165214486.pdf
- https://uploads.strikinglycdn.com/files/7271b8db-359f-4a06-ba00-ba9316488e6b/22916224171.pdf
- https://uploads.strikinglycdn.com/files/9f22f3da-0f81-48c0-843a-e5bde60fc2be/34543766409.pdf
- https://zelapagetuwuj.weebly.com/uploads/1/3/1/4/131406140/xapupevojawogewufu.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/2540998.pdf
- https://razesupimo.weebly.com/uploads/1/3/2/8/132815812/najumekixuvine.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/4106527.pdf
- https://rojusonevupa.weebly.com/uploads/1/3/0/8/130814232/6158153.pdf
- https://cdn.shopify.com/s/files/1/0434/3886/6584/files/zasowesefabi.pdf
- https://cdn.shopify.com/s/files/1/0481/1135/4005/files/oregon_medical_board_fieldprint.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ttraff.club
- uploads.strikinglycdn.com
- cdn.shopify.com
- zelapagetuwuj.weebly.com
- babikovinemixe.weebly.com
- razesupimo.weebly.com
- fijojonibiw.weebly.com
- rojusonevupa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report