SUSPICIOUS — normal_5f86f44824471.pdf
SUSPICIOUS — normal_5f86f44824471.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1cfed5c5efd4106c9581089134b93a9700290d15a9078615585b8dfc7e74bea2 - SHA-1:
116d1947460a94e9580c746ff264acbb763c3d99 - MD5:
46c84e22b3dcb0ce68d8044081c9f8de - ssdeep:
768:YgGzpDheOTUMYx3vN1ynC+A33PoRFpCSYBcWT74/tX6fuVlcN42qA2s87jXoFTOl:1GFNeRx3vNYCNPo3NVSq2qQioF/+ao - TLSH:
T153339EF301B7DC8D3A86EB03B9EA306D5486DB486132E6B054983B1CC5BC6BD7E50A50 - Submitted as: normal_5f86f44824471.pdf
- File type: pdf · Size: 48080 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6a20fae2-3d98-41d5-b39b-30321321cfd3/gefima.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=kaplan+gmat+verbal+pdf, https://cdn.shopify.com/s/files/1/0440/6332/6358/files/7th_grade_argumentative_essay_topics.pdf, https://cdn.shopify.com/s/files/1/0266/9271/4685/files/96175640771.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=kaplan+gmat+verbal+pdf
- https://cdn.shopify.com/s/files/1/0440/6332/6358/files/7th_grade_argumentative_essay_topics.pdf
- https://cdn.shopify.com/s/files/1/0266/9271/4685/files/96175640771.pdf
- https://cdn.shopify.com/s/files/1/0436/2534/9283/files/ribaluzojevob.pdf
- https://cdn.shopify.com/s/files/1/0433/9639/9269/files/girard_awning_manual_override.pdf
- https://cdn.shopify.com/s/files/1/0501/6407/2613/files/836834210.pdf
- https://cdn.shopify.com/s/files/1/0482/7385/0532/files/unblocked_bloons_tower_defense_4.pdf
- https://cdn.shopify.com/s/files/1/0501/6636/6363/files/16877447395.pdf
- https://cdn.shopify.com/s/files/1/0430/5797/1354/files/mijawijigire.pdf
- https://cdn.shopify.com/s/files/1/0438/4138/8709/files/valid_credit_cards_with_cvv_and_expiration_date.pdf
- https://cdn.shopify.com/s/files/1/0434/7186/3961/files/th_9_base_layout_2020.pdf
- https://cdn.shopify.com/s/files/1/0437/5429/1361/files/67162603537.pdf
- https://cdn.shopify.com/s/files/1/0434/2769/2695/files/mars_and_venus_in_the_bedroom_book_download.pdf
- https://uploads.strikinglycdn.com/files/6a20fae2-3d98-41d5-b39b-30321321cfd3/gefima.pdf
- https://uploads.strikinglycdn.com/files/2f689cc2-0064-4ae9-af42-f4feb8c0b7d4/kajemunogerevadiminukadiw.pdf
- https://uploads.strikinglycdn.com/files/639181d6-a188-4898-969f-da04409b7a56/60691281470.pdf
- https://uploads.strikinglycdn.com/files/b70658aa-0382-4e7c-b00d-49f5bc2bf384/gonaroxunijeladadux.pdf
- https://uploads.strikinglycdn.com/files/174cc87b-a3d6-4395-856d-af1fe1873e46/durepopobikawovoneb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.kaptest.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report