SUSPICIOUS — normal_5f982ed51497f.pdf
SUSPICIOUS — normal_5f982ed51497f.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f70399843349da00e39de4c3e8e1c4edc042a456c82d20f667d0570fc8411e31 - SHA-1:
89f154eb67f63ffe3e3fd72c0751c4f13ac4289a - MD5:
9cc3b9411fa53b31677bd6bf7253530a - ssdeep:
768:EgGzpD8p1ovmERR5H9K4LY10VK7S4FWoaj5qx6llAkjW1OP8:xGFQpyVE7S4FWv5tllAka1OP8 - TLSH:
T175328DF36497EC8C7A8B9B4369BB1429604AC3886237976048CC6B2DD57C7BD7F50860 - Submitted as: normal_5f982ed51497f.pdf
- File type: pdf · Size: 44526 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/01eaab51-e7c0-42d7-8d8a-9159996e36f4/37214344631.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.cc/123?keyword=33000+divided+by+12, https://uploads.strikinglycdn.com/files/01eaab51-e7c0-42d7-8d8a-9159996e36f4/37214344631.pdf, https://uploads.strikinglycdn.com/files/39b192a2-d6a9-4722-aa88-74b8edfe41d0/modelo_artista_hermana_profesora.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.cc/123?keyword=33000+divided+by+12
- https://uploads.strikinglycdn.com/files/01eaab51-e7c0-42d7-8d8a-9159996e36f4/37214344631.pdf
- https://uploads.strikinglycdn.com/files/39b192a2-d6a9-4722-aa88-74b8edfe41d0/modelo_artista_hermana_profesora.pdf
- https://uploads.strikinglycdn.com/files/e3c41972-8b8a-4c99-9fb9-2b5f9d430093/76073925837.pdf
- https://cdn.shopify.com/s/files/1/0480/9578/9220/files/xoxutaziligomub.pdf
- https://cdn.shopify.com/s/files/1/0463/8353/0139/files/indesign_print_to_booklet.pdf
- https://cdn.shopify.com/s/files/1/0431/3671/2861/files/manual_testing_questions.pdf
- https://cdn.shopify.com/s/files/1/0465/0860/5590/files/snowline_school_district_jobs.pdf
- https://uploads.strikinglycdn.com/files/7aec6417-7d75-461d-a860-f541f08f4291/witcher_3_gwent.pdf
- https://uploads.strikinglycdn.com/files/2b392171-faed-482a-8819-4298eb8ad881/dasuduw.pdf
- https://uploads.strikinglycdn.com/files/21442be2-4248-49d1-a529-fca11593925d/48159311644.pdf
- https://uploads.strikinglycdn.com/files/c1262c36-70d6-4ac2-9413-8838f057d652/29400061951.pdf
- https://uploads.strikinglycdn.com/files/75506c34-f5f6-467c-9726-32d3d6c957e6/22550344840.pdf
- https://patelevenimo.weebly.com/uploads/1/3/1/4/131437444/2284296.pdf
- https://nadazeva.weebly.com/uploads/1/3/4/4/134499610/saxorajokinegu-mirowurojage.pdf
- https://cdn.shopify.com/s/files/1/0499/7074/1416/files/28558098709.pdf
- https://cdn.shopify.com/s/files/1/0503/0448/3525/files/mafufoxomimofomoruginit.pdf
- https://cdn.shopify.com/s/files/1/0495/9797/2629/files/tabonobijezasofanoti.pdf
- https://uploads.strikinglycdn.com/files/d947ede3-1a92-4a04-a780-bf7e0798038b/cs_16_ecc_indir.pdf
- https://uploads.strikinglycdn.com/files/d0deb365-bb45-47dd-9c76-2b16218a8a8e/majeraxemazumu.pdf
- https://uploads.strikinglycdn.com/files/def6de95-cd27-4d9c-adea-6c24c6daa7e1/35285574440.pdf
- https://uploads.strikinglycdn.com/files/694d0617-aeac-471b-a893-bcb1a31ad55d/badupijaluxomi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ttraff.cc
- uploads.strikinglycdn.com
- cdn.shopify.com
- patelevenimo.weebly.com
- nadazeva.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report