SUSPICIOUS — normal_5f994cb61f3f2.pdf
SUSPICIOUS — normal_5f994cb61f3f2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
187ce64a186d0235c11f93b36e2e201abc007860b03b72e8048860c61adde70b - SHA-1:
254943394f4d3a391350e0841c814b725ad98c46 - MD5:
85c08f0425b2417a083bf743a3daffed - ssdeep:
768:QgGzpDbVca+14h7BgKRlrclXznU1WlPhphgxsrAJUNr7gKXWeZPUfZxI:9GFXM3KfmUYlPJgxcACrDXWeZPaZxI - TLSH:
T1C8328EF35197ED8CBB8B9B179DBA20595046C78CA232DB6044CC7B2CC5BC6EDAD01960 - Submitted as: normal_5f994cb61f3f2.pdf
- File type: pdf · Size: 45577 bytes
- Verdict: suspicious (58/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/24fa9870-c112-4620-8b25-b20a051b6514/45460621054.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ttraff.ru/123?keyword=1995+ford+mustang+gt+5.0+horsepower, https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/bosilo_ginasesif.pdf, https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/bazoliv.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ttraff.ru/123?keyword=1995+ford+mustang+gt+5.0+horsepower
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/bosilo_ginasesif.pdf
- https://digonowokeke.weebly.com/uploads/1/3/1/8/131856318/bazoliv.pdf
- https://daletutanedura.weebly.com/uploads/1/3/1/6/131636587/jigakikuvomapi.pdf
- https://xomevore.weebly.com/uploads/1/3/4/3/134346529/e84a521.pdf
- https://kelobutino.weebly.com/uploads/1/3/0/9/130969458/semipitipobusaleja.pdf
- https://cdn-cms.f-static.net/uploads/4373522/normal_5f90c54ece9f4.pdf
- https://uploads.strikinglycdn.com/files/8c628c07-e8c5-4157-a86e-a498659d8447/2008_ford_focus_manual_transmission.pdf
- https://cdn-cms.f-static.net/uploads/4390661/normal_5f923130b588d.pdf
- https://cdn-cms.f-static.net/uploads/4365646/normal_5f8cb7ba62d8c.pdf
- https://uploads.strikinglycdn.com/files/24fa9870-c112-4620-8b25-b20a051b6514/45460621054.pdf
- https://libizewixowu.weebly.com/uploads/1/3/4/4/134432873/fazatogasi-bolovo-kevejisexape.pdf
- https://rizenorugeworo.weebly.com/uploads/1/3/4/3/134379336/4571272.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/kadupe_ripovu_jozovagazemewe.pdf
- https://uploads.strikinglycdn.com/files/1ab41848-929b-4aae-b3eb-3f61e748fd44/xanejetusesavaxoduzanij.pdf
- https://cdn-cms.f-static.net/uploads/4367912/normal_5f8f1a12272a2.pdf
- https://rugurujumififez.weebly.com/uploads/1/3/1/3/131384765/7759758.pdf
- https://uploads.strikinglycdn.com/files/d745f257-a4b5-43b1-b67e-493e7aabaaf6/fipapovasovuvugokewoxivap.pdf
- https://uploads.strikinglycdn.com/files/e95c9359-0fe9-4cb0-9537-eba52f8d9d0e/bakezajabometezijativu.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f871730b8caf.pdf
- https://uploads.strikinglycdn.com/files/b3419fff-ed82-4975-9647-c5e4099916d8/ratuvijipikizisomaba.pdf
- https://uploads.strikinglycdn.com/files/c5d27046-ca6b-417a-a281-324be41e73d3/zumafidu.pdf
- https://cdn-cms.f-static.net/uploads/4370791/normal_5f928b6223860.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ttraff.ru
- mogilifus.weebly.com
- digonowokeke.weebly.com
- daletutanedura.weebly.com
- xomevore.weebly.com
- kelobutino.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- libizewixowu.weebly.com
- rizenorugeworo.weebly.com
- gimejexoxixaza.weebly.com
- rugurujumififez.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report