SUSPICIOUS — normal_5f90694b95100.pdf
SUSPICIOUS — normal_5f90694b95100.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
17375f9db9e4174cd822674a97aa8df0d7b090a5ee296eff2c8e159bffa7f28d - SHA-1:
debdae03750328b4f12f8fc2247ffc16e981f7e3 - MD5:
3cb439c39a1ccee196cf4e872f9e964c - ssdeep:
768:fgGzpD0ppBSFxkghDGWU3TIQ2PEfs+34XKAO+prmlsJa75BKSg7J27tV2a5O:oGFOp5IJyOO+pilskg45j5O - TLSH:
T124327DF710D7EC8C7E8B9F075EAB116D908AD3CD6136A7905488632CD4BCAED6E00961 - Submitted as: normal_5f90694b95100.pdf
- File type: pdf · Size: 44859 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4367961/normal_5f88228e6222d.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=download+vidmate+apk+untuk+ios, https://cdn-cms.f-static.net/uploads/4387243/normal_5f8da78147cce.pdf, https://cdn-cms.f-static.net/uploads/4366399/normal_5f8781be011a1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=download+vidmate+apk+untuk+ios
- https://cdn-cms.f-static.net/uploads/4387243/normal_5f8da78147cce.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f8781be011a1.pdf
- https://cdn-cms.f-static.net/uploads/4371806/normal_5f893417cafc0.pdf
- https://cdn-cms.f-static.net/uploads/4368970/normal_5f8cba06111a4.pdf
- https://cdn-cms.f-static.net/uploads/4367961/normal_5f88228e6222d.pdf
- https://cdn.shopify.com/s/files/1/0500/7435/3850/files/ogame_quick_build_guide.pdf
- https://cdn.shopify.com/s/files/1/0480/6190/7108/files/19158023417.pdf
- https://uploads.strikinglycdn.com/files/8281ce11-9fcb-4491-b9ed-46b281f9e76e/43899107309.pdf
- https://uploads.strikinglycdn.com/files/cc9894a4-895a-4d13-80a6-80ac05ee0bbd/dumukebisur.pdf
- https://uploads.strikinglycdn.com/files/e9f71eae-ed54-43fc-94ee-6bf57a8842a5/72093240236.pdf
- https://uploads.strikinglycdn.com/files/7229ea6c-71af-4453-9d6f-d7728932c2ce/92697493797.pdf
- https://uploads.strikinglycdn.com/files/f51012c3-2317-4f42-bf8f-9aef62697844/manual_transmission_tips_reddit.pdf
- https://uploads.strikinglycdn.com/files/026893be-680d-4ad9-893e-6509a521a80e/rurajurepejesonoxosabaf.pdf
- https://uploads.strikinglycdn.com/files/4a2c59d1-3f85-43c7-b156-c6d66788ca2e/deroruramazafesazozoxot.pdf
- https://uploads.strikinglycdn.com/files/28bedac6-f865-438e-a562-f915c380acb0/liwukife.pdf
- https://uploads.strikinglycdn.com/files/07065dc8-6309-4356-bcd6-bd203728c9c7/sugopixikekisitigirem.pdf
- https://uploads.strikinglycdn.com/files/8891a6a2-f434-4663-9df1-e892ccd76977/beniburobatexowaxokapipe.pdf
- https://uploads.strikinglycdn.com/files/b0019f77-8ca5-4e6a-a0a0-c2e6e8d125d7/wobuwumaroketoxe.pdf
- https://uploads.strikinglycdn.com/files/4160ecaf-de5f-48cf-bb61-a1c977c6938c/rivifadad.pdf
- https://uploads.strikinglycdn.com/files/f053a79e-7f44-4c09-b1a6-2d44aa8074fb/zoripufokebowow.pdf
- https://uploads.strikinglycdn.com/files/ee9b41cf-2683-4a36-b21e-c6feb9ff955b/78738296998.pdf
- https://s3.amazonaws.com/henghuili-files/99527790168.pdf
- https://s3.amazonaws.com/zetare/telecharger_la_boite_a_merveille_complet.pdf
- https://s3.amazonaws.com/leguvefu/18590516037.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report