SUSPICIOUS — normal_5f8be49b45593.pdf
SUSPICIOUS — normal_5f8be49b45593.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
297640f776eef2cba5beab0f6051451f392db76af6d544e30c0b5d867d9385d7 - SHA-1:
6f084743ac91637c3f7de9624ad8c58ce22145dd - MD5:
fcaa5244dcca2b05b2e75d7ebba0572a - ssdeep:
1536:yGFCehwwPOpaCNWszKGBhU5AFtoUW4ypoTZnmsH+U:rFCehwwMaCN9egW4msZ9 - TLSH:
T1CD36AEF350DBDD8CBA83BB43ADEB1166548E874872679B60548C7A2CC4BC6BD3E01950 - Submitted as: normal_5f8be49b45593.pdf
- File type: pdf · Size: 67893 bytes
- Verdict: suspicious (58/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/795ab2f7-485c-413e-a2a9-0e5babe73d62/liretedikiw.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=stanley+45+plow+plane+manual, https://uploads.strikinglycdn.com/files/795ab2f7-485c-413e-a2a9-0e5babe73d62/liretedikiw.pdf, https://uploads.strikinglycdn.com/files/6a947eb2-6977-40d3-a195-ba2fdb30f945/kuwipukadigo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=stanley+45+plow+plane+manual
- https://uploads.strikinglycdn.com/files/795ab2f7-485c-413e-a2a9-0e5babe73d62/liretedikiw.pdf
- https://uploads.strikinglycdn.com/files/6a947eb2-6977-40d3-a195-ba2fdb30f945/kuwipukadigo.pdf
- https://uploads.strikinglycdn.com/files/d6324d93-a2ec-4048-84b2-f472c1815ec2/nebetanirixevejekubasosod.pdf
- https://uploads.strikinglycdn.com/files/fc196589-68b4-4f78-bbce-3a0dbbc2340c/86308440364.pdf
- https://cdn-cms.f-static.net/uploads/4369796/normal_5f8a839b56fc3.pdf
- https://cdn-cms.f-static.net/uploads/4366654/normal_5f8735d0ce7cd.pdf
- https://cdn-cms.f-static.net/uploads/4366015/normal_5f871caac70d8.pdf
- https://uploads.strikinglycdn.com/files/9d57bbd3-bdb1-4ebb-9545-d63e708f028f/69575400898.pdf
- https://uploads.strikinglycdn.com/files/c770c2c4-acc3-44d6-99c5-8bb3e62285d2/90512481259.pdf
- https://uploads.strikinglycdn.com/files/2567fadd-aa44-47d2-b052-7adc4dd60214/mabarujafunezujig.pdf
- https://uploads.strikinglycdn.com/files/e0d1efe9-af49-4e72-8242-44e627284ec8/2007302397.pdf
- https://uploads.strikinglycdn.com/files/49cbbb2f-ca71-4270-8daa-d3b95fc86e54/gomagufexofav.pdf
- https://uploads.strikinglycdn.com/files/815afb79-0caa-49c1-85ed-77c1c17734c6/pokikarevux.pdf
- https://uploads.strikinglycdn.com/files/645e5611-70a6-4a99-8dde-59d341288a99/96722684726.pdf
- https://uploads.strikinglycdn.com/files/bc3c8fdf-1bd3-41c8-b7a9-1a9d84b7ea1b/55281835613.pdf
- https://uploads.strikinglycdn.com/files/86bc0269-c42d-40ec-af36-78961b171c64/pulobipizutelawez.pdf
- https://uploads.strikinglycdn.com/files/e356d2d0-0bd7-4592-80bd-0b5268c8e7eb/96119230745.pdf
- https://uploads.strikinglycdn.com/files/426f9fd1-f90b-4974-94ff-7a567996e006/nudadegatomonita.pdf
- https://uploads.strikinglycdn.com/files/a1aec6f1-ea27-4dab-b747-d6556db505e8/gonabemugajuvaxex.pdf
- https://mupibidegupek.weebly.com/uploads/1/3/0/8/130874042/72a6de9b.pdf
- https://kinojapi.weebly.com/uploads/1/3/2/3/132302846/bdebf7.pdf
- https://jumuwubugunitus.weebly.com/uploads/1/3/1/0/131070493/resatet.pdf
- https://tudupumodowi.weebly.com/uploads/1/3/1/4/131406798/b726ec796bb5.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/9b6e7aadaa78.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- mupibidegupek.weebly.com
- kinojapi.weebly.com
- jumuwubugunitus.weebly.com
- tudupumodowi.weebly.com
- mojivimimujovo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report