SUSPICIOUS — normal_5f887ba65a906.pdf
SUSPICIOUS — normal_5f887ba65a906.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
15b7bf67d8bb23cfd7c276e713f9efacf78cdff6bd567a0b8dfc40d5f05f3d5c - SHA-1:
77bafff0ff76301f888f7833b2002224be119afc - MD5:
1a5a954e69d4faad7fa2de19b969f64f - ssdeep:
1536:tGFNp4VC7A6QdX43RN//Kv4Yo/8ohfZ/iW2O8DxjrwEB9l5yj2x:wFNp4ss6QdyR9KFxu/cvdHTLoI - TLSH:
T14036AFF3109BDC8C3ACEAB07AAAB0528644A8B497132DBD055CC776CD57C9EDAE10611 - Submitted as: normal_5f887ba65a906.pdf
- File type: pdf · Size: 69120 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/8ff815b9-e43a-46cd-b616-09a1173f025c/27365588436.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=baixar+livro+budismo+pdf, https://uploads.strikinglycdn.com/files/8ff815b9-e43a-46cd-b616-09a1173f025c/27365588436.pdf, https://uploads.strikinglycdn.com/files/9a5cf347-8d95-484e-9ced-b9aa3f216250/93317810495.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=baixar+livro+budismo+pdf
- https://uploads.strikinglycdn.com/files/8ff815b9-e43a-46cd-b616-09a1173f025c/27365588436.pdf
- https://uploads.strikinglycdn.com/files/9a5cf347-8d95-484e-9ced-b9aa3f216250/93317810495.pdf
- https://uploads.strikinglycdn.com/files/0bfae1b8-b094-4fcf-98ad-6f19d9a11a76/mukuz.pdf
- https://uploads.strikinglycdn.com/files/c74ce129-2a39-4038-b881-84c50f728825/5335919630.pdf
- https://uploads.strikinglycdn.com/files/c42a39ec-7d5c-44ef-9450-d3ebf2d98160/bowuf.pdf
- https://cdn.shopify.com/s/files/1/0434/5767/5431/files/goulds_pathophysiology_for_the_health_professions_5th_edition_free.pdf
- https://cdn.shopify.com/s/files/1/0496/7756/6109/files/60459465332.pdf
- https://cdn.shopify.com/s/files/1/0484/1347/4984/files/pewodafirewat.pdf
- https://cdn.shopify.com/s/files/1/0483/5973/5447/files/54250703475.pdf
- https://cdn.shopify.com/s/files/1/0482/2702/5050/files/glencoe_world_history_modern_times_quizzes_and_tests_answers.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f87277bb7771.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f874901752e0.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f8741263fd9e.pdf
- https://site-1039393.mozfiles.com/files/1039393/27677197030.pdf
- https://site-1038879.mozfiles.com/files/1038879/download_avengers_game_for_android_phones.pdf
- https://site-1043258.mozfiles.com/files/1043258/24362819082.pdf
- https://cdn.shopify.com/s/files/1/0483/7297/3728/files/mystery_power_box_7.pdf
- https://cdn.shopify.com/s/files/1/0481/0509/5331/files/lofeziludebotisamogomog.pdf
- https://cdn.shopify.com/s/files/1/0436/1843/5229/files/quien_invento_el_telefono_inalambrico.pdf
- https://cdn.shopify.com/s/files/1/0495/8991/1715/files/79035021727.pdf
- https://cdn.shopify.com/s/files/1/0486/6664/0534/files/what_is_the_equivalent_resistance_of_two_12_ohm_resistors_connected_in_series.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f870fb51a94a.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f8813576a343.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f87490f73b4f.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1039393.mozfiles.com
- site-1038879.mozfiles.com
- site-1043258.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report