SUSPICIOUS — normal_5fa61ea676e54.pdf
SUSPICIOUS — normal_5fa61ea676e54.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ee7c24e28d795a49c0cd14c71606c7a0691f4ceed6b2cd3a7be941e7348cd946 - SHA-1:
799a610ebb53239dc5cef8d65cf3c6f53cf36469 - MD5:
821bd965819a84b3f51aae320f8eb22f - ssdeep:
768:wgGzpDs5goni/xbuoHWxUd/MJhWSaKcfdYS0L0cj/HDnMTB2:dGF4556v2xUpMUdV40FTB2 - TLSH:
T150327CF310A7CD8C7B86AB0369A6145AA18BC749612696B0049D7B7C84FC7FD3F40E61 - Submitted as: normal_5fa61ea676e54.pdf
- File type: pdf · Size: 43735 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5555510a-315e-4d96-9749-d32eff78ed2e/gonowufufijuxereg.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=nonlinear+functions+worksheet, https://cdn-cms.f-static.net/uploads/4370307/normal_5f9782e98380f.pdf, https://uploads.strikinglycdn.com/files/5555510a-315e-4d96-9749-d32eff78ed2e/gonowufufijuxereg.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=nonlinear+functions+worksheet
- https://s3.amazonaws.com/pibajuwi/get_over_your_damn_self_quotes.pdf
- https://cdn-cms.f-static.net/uploads/4370307/normal_5f9782e98380f.pdf
- https://s3.amazonaws.com/lanowilovuviwib/carbon_disulfide_lewis_structure.pdf
- https://uploads.strikinglycdn.com/files/5555510a-315e-4d96-9749-d32eff78ed2e/gonowufufijuxereg.pdf
- https://uploads.strikinglycdn.com/files/d4bfc342-8d9f-4422-bec6-c05e3cfa1a07/gaxidonojevimozu.pdf
- https://s3.amazonaws.com/pazerogasarinu/mefipugafutibifazobipas.pdf
- https://uploads.strikinglycdn.com/files/03f9e868-d798-4c12-9634-80a93c9d73c0/investigation_vs_perception.pdf
- https://dinoromakutaxe.weebly.com/uploads/1/3/4/4/134479472/2b64f7f.pdf
- https://cdn-cms.f-static.net/uploads/4374189/normal_5f9d5c75cec85.pdf
- https://zegojipoxe.weebly.com/uploads/1/3/1/0/131069766/doxupozikodowe-gebosedu-desamomat.pdf
- https://nitetezelimon.weebly.com/uploads/1/3/1/4/131438651/vefem.pdf
- https://lepebixetuvenal.weebly.com/uploads/1/3/4/6/134634058/nokatizagogusow.pdf
- https://siregudak.weebly.com/uploads/1/3/0/7/130738759/wenowamopa_berowagelo_lawiwitovevisom.pdf
- https://s3.amazonaws.com/sigobija/car_door_seal_repair.pdf
- https://s3.amazonaws.com/pazovugal/67310799620.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- dinoromakutaxe.weebly.com
- zegojipoxe.weebly.com
- nitetezelimon.weebly.com
- lepebixetuvenal.weebly.com
- siregudak.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report