SUSPICIOUS — normal_5f8939ea061e7.pdf
SUSPICIOUS — normal_5f8939ea061e7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
189bf688a683cb8551f58c66df7933985bd6490d21888a551d971cc2afcf7e4e - SHA-1:
22ff9d044493177ba96e8d5f1ac20b16c5091d64 - MD5:
7b05a0cb151f0f22ab98c5ccde7fa8df - ssdeep:
1536:4GF6p0EmZqgn/BYFKBws4EyzstTGKhrR:VF6p0Fq+/BYFKBkItTGA - TLSH:
T1DF349EF750E7EC8C7A8B6F03AEA70158A05EC789703697904188672DC4BCAFD7E50A50 - Submitted as: normal_5f8939ea061e7.pdf
- File type: pdf · Size: 53970 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/5d8277f5-3f9b-491e-998d-96eca9956e20/fakanugatevowupumoj.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=first+strike+final+hour+apk+mod, https://cdn.shopify.com/s/files/1/0437/5930/4858/files/prentice_hall_united_states_history_online_textbook.pdf, https://cdn.shopify.com/s/files/1/0266/9536/8876/files/clat_exam_2020_question_paper.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=first+strike+final+hour+apk+mod
- https://cdn.shopify.com/s/files/1/0482/1870/1978/files/84884647695.pdf
- https://cdn.shopify.com/s/files/1/0437/5930/4858/files/prentice_hall_united_states_history_online_textbook.pdf
- https://cdn.shopify.com/s/files/1/0266/9536/8876/files/clat_exam_2020_question_paper.pdf
- https://cdn.shopify.com/s/files/1/0434/8513/5014/files/scope_resolution_operator_in_kotlin.pdf
- https://cdn.shopify.com/s/files/1/0480/8671/2484/files/kopeb.pdf
- https://derodaju.weebly.com/uploads/1/3/1/6/131606282/xotal_todus_jemebadava.pdf
- https://fijojonibiw.weebly.com/uploads/1/3/2/6/132681787/5648329.pdf
- https://fewevivib.weebly.com/uploads/1/3/0/8/130813821/5653360.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/6955789.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/wogiselaruto-nokage.pdf
- https://cdn-cms.f-static.net/uploads/4370307/normal_5f8808c878948.pdf
- https://cdn-cms.f-static.net/uploads/4366304/normal_5f875d520c965.pdf
- https://cdn-cms.f-static.net/uploads/4367632/normal_5f8748a93c2d6.pdf
- https://uploads.strikinglycdn.com/files/5d8277f5-3f9b-491e-998d-96eca9956e20/fakanugatevowupumoj.pdf
- https://uploads.strikinglycdn.com/files/5c60eca9-0eb7-4e2c-a033-2a1524ccba26/fejodaxeverusetev.pdf
- https://uploads.strikinglycdn.com/files/8222bc24-a52b-4649-9f2d-0d4dde417115/91914757854.pdf
- https://uploads.strikinglycdn.com/files/497565c1-8224-4fe1-9ee7-a9067e1c4121/gudigatatagupaxabuxeri.pdf
- https://uploads.strikinglycdn.com/files/1b7a60ab-0bb6-4f88-9af8-a64945341795/mizug.pdf
- https://uploads.strikinglycdn.com/files/876790c2-c794-4d48-ac11-2c705e80aa30/kidagijakuveposijo.pdf
- https://uploads.strikinglycdn.com/files/914baac3-52f7-4fe3-8f64-4f43d0b71dfd/teluwoxiwewipu.pdf
- https://uploads.strikinglycdn.com/files/53a4f44c-7f02-4ea2-b391-77e9f421ce68/sinozufor.pdf
- https://uploads.strikinglycdn.com/files/7f1b116f-3c09-43f3-9048-b70c835dc18a/10953534675.pdf
- https://uploads.strikinglycdn.com/files/762f8abe-5a7b-4a12-97d6-d553b707c05b/58618978809.pdf
- https://uploads.strikinglycdn.com/files/3636aaae-cecc-4d79-8e4a-6fbb770a6a1d/88864650729.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- derodaju.weebly.com
- fijojonibiw.weebly.com
- fewevivib.weebly.com
- genigudepa.weebly.com
- xojerajap.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report