SUSPICIOUS — normal_5f99b24d4d299.pdf
SUSPICIOUS — normal_5f99b24d4d299.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
28020f9bb03fa02616a170b7552a52dd3014cce92d3b1a8825c0d167357d9c6d - SHA-1:
22a750b553a18036f3e0d8496adc6e97e77a2c6c - MD5:
5a4f2c9eddcb3ab6200e4ceae9b4f62c - ssdeep:
768:MgGzpDQOxyNVFGiX5WZZdIqcckqfhhNWqJBmqV4wZpqjo552e:JGFUOcNRJSIqUShfB5V4Sqjo552e - TLSH:
T184317DF350D7DD8C7A8BAF075DB6205E6189C688B23297A059DC772C88BC6ED6D00C51 - Submitted as: normal_5f99b24d4d299.pdf
- File type: pdf · Size: 40991 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/324872a3-ce8a-4b51-970b-5ee01599c3e4/gemefukuwiwerugu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=graphing+quadratics+quiz+answers, https://uploads.strikinglycdn.com/files/324872a3-ce8a-4b51-970b-5ee01599c3e4/gemefukuwiwerugu.pdf, https://uploads.strikinglycdn.com/files/fa4f4bed-bf41-40a9-be86-583848be71eb/49425354298.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=graphing+quadratics+quiz+answers
- https://s3.amazonaws.com/salosibejodod/english_to_hindi_word_meaning_dictionary.pdf
- https://s3.amazonaws.com/regovadeje/49562749716.pdf
- https://uploads.strikinglycdn.com/files/324872a3-ce8a-4b51-970b-5ee01599c3e4/gemefukuwiwerugu.pdf
- https://s3.amazonaws.com/henghuili-files2/mofemonalezo.pdf
- https://uploads.strikinglycdn.com/files/fa4f4bed-bf41-40a9-be86-583848be71eb/49425354298.pdf
- https://gexumuvebevo.weebly.com/uploads/1/3/4/3/134312536/fixizedinalokuxo.pdf
- https://soxajenukaru.weebly.com/uploads/1/3/0/8/130874283/gabevimegupuvun-vunesixoge-nagekenesema.pdf
- https://mobonojijokatu.weebly.com/uploads/1/3/4/3/134320628/4102329.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/67f7767f9a8dfa.pdf
- https://uploads.strikinglycdn.com/files/8089aaad-4905-437d-90bb-271e8d9ee489/sifukaki.pdf
- https://xazapadikud.weebly.com/uploads/1/3/1/8/131871762/7230269.pdf
- https://s3.amazonaws.com/lekizopiloref/55847334657.pdf
- https://joleziravakejar.weebly.com/uploads/1/3/4/4/134460301/6c6da9.pdf
- https://koxoganonigowup.weebly.com/uploads/1/3/1/4/131408343/pikumavow-tekedaropegafeg-gufurej-jenew.pdf
- https://jezafemobad.weebly.com/uploads/1/3/1/3/131383748/9163394.pdf
- https://povutepumik.weebly.com/uploads/1/3/2/7/132741486/4b201c87d.pdf
- https://cdn-cms.f-static.net/uploads/4374840/normal_5f94a17cac980.pdf
- https://s3.amazonaws.com/fejenijovekozu/tasugotikavujuruxup.pdf
- https://s3.amazonaws.com/susopuzupure/gitadiz.pdf
- https://vogizezadu.weebly.com/uploads/1/3/0/8/130814341/098659e5887e723.pdf
- https://cdn-cms.f-static.net/uploads/4371791/normal_5f8be61b6c39d.pdf
- https://s3.amazonaws.com/dovulavavo/97054257529.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- gexumuvebevo.weebly.com
- soxajenukaru.weebly.com
- mobonojijokatu.weebly.com
- zesopupejilit.weebly.com
- xazapadikud.weebly.com
- joleziravakejar.weebly.com
- koxoganonigowup.weebly.com
- jezafemobad.weebly.com
- povutepumik.weebly.com
- cdn-cms.f-static.net
- vogizezadu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report