SUSPICIOUS — normal_5f8d885e5da4e.pdf
SUSPICIOUS — normal_5f8d885e5da4e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ec36388f9c9433dbc7adeecc44f667a64fb9498af8c8989fcbb2b58a221d8f72 - SHA-1:
7d94c1c3381e6e70f236fc94c49c06c0b1dadd89 - MD5:
1b7dfb0b6c47b88a8b467de43c88711a - ssdeep:
1536:BGFtpKDd11J7J3a6QY8Esv53xDvygswTpTMb:kFtpKDd11JRrQr399Y - TLSH:
T1BE36BEF361E3EC4CBA8A5B03AEA7969C608D9789523796500488731DC4BC3FE7F10961 - Submitted as: normal_5f8d885e5da4e.pdf
- File type: pdf · Size: 68933 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/840d257a-5c69-4315-9563-0b7b406841e6/26950199633.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.me/123?keyword=dravyaguna+vigyan+book+pdf+free+download, https://cdn-cms.f-static.net/uploads/4368228/normal_5f8d4f444f916.pdf, https://cdn-cms.f-static.net/uploads/4370307/normal_5f8b4fe217094.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.me/123?keyword=dravyaguna+vigyan+book+pdf+free+download
- https://cdn-cms.f-static.net/uploads/4368228/normal_5f8d4f444f916.pdf
- https://cdn-cms.f-static.net/uploads/4370307/normal_5f8b4fe217094.pdf
- https://cdn-cms.f-static.net/uploads/4366408/normal_5f89bfdab770f.pdf
- https://cdn-cms.f-static.net/uploads/4368953/normal_5f886fd3ada54.pdf
- https://cdn-cms.f-static.net/uploads/4368471/normal_5f8821e3e88ee.pdf
- https://uploads.strikinglycdn.com/files/840d257a-5c69-4315-9563-0b7b406841e6/26950199633.pdf
- https://uploads.strikinglycdn.com/files/0aee3509-d9aa-47f0-a281-00a84e3b2b9e/vekelupuduteneba.pdf
- https://uploads.strikinglycdn.com/files/08824705-e21c-4455-9822-880b1c3eec2f/22834646645.pdf
- https://uploads.strikinglycdn.com/files/eaebaa3f-d684-46fe-8e78-992feb9a3844/robbins_pathologic_basis_of_disease.pdf
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/6446207.pdf
- https://temazojirilezin.weebly.com/uploads/1/3/2/3/132302863/8d4787a.pdf
- https://cdn-cms.f-static.net/uploads/4375356/normal_5f8a1e316dc99.pdf
- https://cdn-cms.f-static.net/uploads/4369663/normal_5f8a1b8c1876b.pdf
- https://cdn-cms.f-static.net/uploads/4383444/normal_5f8d6e2a79b6e.pdf
- https://cdn-cms.f-static.net/uploads/4376371/normal_5f8a24d3b0228.pdf
- https://uploads.strikinglycdn.com/files/ff4f27db-45ba-45b4-922a-6d435a598c96/24021319157.pdf
- https://uploads.strikinglycdn.com/files/f8d8ce27-bd7b-4604-91b4-34c73992b017/71507239316.pdf
- https://uploads.strikinglycdn.com/files/51e48b68-41dc-4d41-a0fe-818a0b9372d9/mewanose.pdf
- https://uploads.strikinglycdn.com/files/8b1a9a99-7e1d-4568-8d73-b3e6cdc72dc6/bekemapufalap.pdf
- https://uploads.strikinglycdn.com/files/982ae56d-9f0b-476f-a679-7bc4c5c112da/jijepevixom.pdf
- https://uploads.strikinglycdn.com/files/e1b1e2a4-6825-46a7-b5ef-e0ca4fd2b358/lapejinisibukababofu.pdf
- https://uploads.strikinglycdn.com/files/d1320bad-3428-4a1c-a0c8-3a7dc61e17c9/bixevovirobobapi.pdf
- https://uploads.strikinglycdn.com/files/b6e3c964-8bef-4998-809c-ab106d624f54/84637992287.pdf
- https://uploads.strikinglycdn.com/files/59719905-5b74-4add-93cc-2fde01144deb/80026563019.pdf
Embedded domains
- ttraff.me
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- digonowokeke.weebly.com
- temazojirilezin.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report