SUSPICIOUS — normal_5f8dfe617acd5.pdf
SUSPICIOUS — normal_5f8dfe617acd5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e791ebf5ae6689fd6f1732fa475b0dc4387feeee9bca93b445fa70a6330409a5 - SHA-1:
8c58428cb2934d2b8b2186bd8d984d47bc5309cb - MD5:
a65bc6cd116c509e521a6a1cb095a4d8 - ssdeep:
768:wYgGzpDBpakhFDSvA7XZp73msGcKq4DuPBazQxZm9aKwfIJTugZb/V3nmCFmglg:UGFtpakKqd8zQx5KweTZZb/V3nmCQglg - TLSH:
T1C5327CF31193DD0C7A8BAF43ADEA142E924AD3495232A7B0548C672CD4BC7AD3F04A51 - Submitted as: normal_5f8dfe617acd5.pdf
- File type: pdf · Size: 46981 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/070d860d-af8e-4f45-a5f0-0a172516d023/17050768814.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.ru/123?keyword=beats+powerbeats+pro+android, https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/185513.pdf, https://patelevenimo.weebly.com/uploads/1/3/1/4/131437444/4302934.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=beats+powerbeats+pro+android
- https://moxitasa.weebly.com/uploads/1/3/1/4/131454719/185513.pdf
- https://patelevenimo.weebly.com/uploads/1/3/1/4/131437444/4302934.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/09b03b.pdf
- https://wivupenoremew.weebly.com/uploads/1/3/0/7/130775018/378398.pdf
- https://uploads.strikinglycdn.com/files/070d860d-af8e-4f45-a5f0-0a172516d023/17050768814.pdf
- https://uploads.strikinglycdn.com/files/eed73dc6-a7cf-4775-ba27-bff3bb8b06c5/jokazetogo.pdf
- https://uploads.strikinglycdn.com/files/6cb60371-9cc1-493f-94bb-4fc44af79209/xesemoxasivon.pdf
- https://uploads.strikinglycdn.com/files/6e246d82-87f0-456e-82c9-902e035e6382/fotexedola.pdf
- https://uploads.strikinglycdn.com/files/63c47633-bc87-4e17-bb46-9bdcb95425c4/ropalovejebujufudaz.pdf
- https://cdn.shopify.com/s/files/1/0266/9264/9132/files/2-8-2_mikado_length.pdf
- https://cdn.shopify.com/s/files/1/0494/0270/8135/files/double_digit_multiplying_worksheets.pdf
- https://sakuvajavabese.weebly.com/uploads/1/3/1/3/131383602/gotilu_mepanerarofizo_diwogadefire.pdf
- https://xavoxoxuda.weebly.com/uploads/1/3/1/3/131379246/9259492.pdf
- https://dojulukasinu.weebly.com/uploads/1/3/0/7/130776790/livefoze.pdf
- https://xilorufanil.weebly.com/uploads/1/3/0/7/130739938/4b34ede87a7c2e5.pdf
- https://cdn.shopify.com/s/files/1/0433/8099/8298/files/nupadawawatu.pdf
- https://cdn.shopify.com/s/files/1/0431/9644/8917/files/masters_of_menace_trailer.pdf
- https://cdn.shopify.com/s/files/1/0266/9740/0517/files/46349354410.pdf
- https://cdn.shopify.com/s/files/1/0495/1421/7638/files/college_basketball_recruiting_guidelines.pdf
- https://cdn.shopify.com/s/files/1/0433/9499/0247/files/the_best_american_essays_download.pdf
- https://cdn.shopify.com/s/files/1/0501/1505/1685/files/ice_catcher_water_bong.pdf
- https://cdn.shopify.com/s/files/1/0484/6623/1446/files/5_languages_of_love_test_in_spanish.pdf
- https://cdn.shopify.com/s/files/1/0430/5901/9933/files/super_nintendo_emulator_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0476/7481/8726/files/turbo_pascal_book.pdf
Embedded domains
- ttraff.ru
- moxitasa.weebly.com
- patelevenimo.weebly.com
- jatorogerujew.weebly.com
- wivupenoremew.weebly.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- sakuvajavabese.weebly.com
- xavoxoxuda.weebly.com
- dojulukasinu.weebly.com
- xilorufanil.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report