SUSPICIOUS — normal_5f87436a9446a.pdf
SUSPICIOUS — normal_5f87436a9446a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2717f7d47c09a60b8f7bc0a083c16eb76d9a242d4c4612ee68c3e14d7dfe97fe - SHA-1:
aa7cf576de36690625cb143ebd1fea58da62b34e - MD5:
1e0f78df54f77a3d2c6b360e658c0f4f - ssdeep:
768:2gGzpDqpaySl1dd01FXnmqOUgRik9vCvrAmb6m8C4n+m7i5CNHGo1JqxNUgw2duk:jGFOpml1ddyWxm8Rm5CNH1n86vEu4Io - TLSH:
T13C339DF341A3EC4C7A8A9B53B8FB11AAA04DD7886172A764458C772CC47C6FD7E40A41 - Submitted as: normal_5f87436a9446a.pdf
- File type: pdf · Size: 49165 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ee547870-de02-4a42-8031-a36c93c5929b/12003227389.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=guided+bus+leigh+to+manchester, https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/5145133.pdf, https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/3067697.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=guided+bus+leigh+to+manchester
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/5145133.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/3067697.pdf
- https://jufaxexave.weebly.com/uploads/1/3/0/7/130775513/ab58f1a83d861e.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/vaxukekiwurefebe.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/83905a54a030772.pdf
- https://cdn.shopify.com/s/files/1/0431/7590/3392/files/government_study_guide_answers.pdf
- https://cdn.shopify.com/s/files/1/0494/4635/5103/files/36542132437.pdf
- https://cdn.shopify.com/s/files/1/0437/1306/9205/files/pubarewix.pdf
- https://cdn.shopify.com/s/files/1/0434/4158/6332/files/accounting_equation_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0431/8868/2915/files/wafudojaxiwebunerarala.pdf
- https://uploads.strikinglycdn.com/files/ee547870-de02-4a42-8031-a36c93c5929b/12003227389.pdf
- https://uploads.strikinglycdn.com/files/244cca39-45b4-4d74-957f-cb428bd88dac/86592884527.pdf
- https://cdn.shopify.com/s/files/1/0434/9670/2104/files/xadadaloxawapewibedisof.pdf
- https://cdn.shopify.com/s/files/1/0482/1912/7965/files/skills_worksheet_concept_review_section_female_reproductive_system_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0439/4916/2654/files/gogogajuxifinemub.pdf
- https://cdn.shopify.com/s/files/1/0496/0023/3636/files/harry_potter_y_el_prisionero_de_azkaban_pelcula_completa_facebook.pdf
- https://cdn.shopify.com/s/files/1/0482/8335/3249/files/measuring_mass_worksheet_grade_2.pdf
- https://cdn.shopify.com/s/files/1/0438/4060/2269/files/gamowasizopozam.pdf
- https://uploads.strikinglycdn.com/files/032495ec-e2ed-40cf-a7b6-e7145b3f5d0f/82406532673.pdf
- https://uploads.strikinglycdn.com/files/2934a9bd-8a13-4ea0-b07b-2ca47617efe9/16187832688.pdf
- https://uploads.strikinglycdn.com/files/9ca89983-e98f-432d-a7d2-066d858ee143/5644555060.pdf
- https://uploads.strikinglycdn.com/files/1b3a7a44-e046-447f-85a2-c5c98e67a09a/48665280798.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- wepugimi.weebly.com
- walijogopabo.weebly.com
- jufaxexave.weebly.com
- keniwuki.weebly.com
- jakedekokobara.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report