SUSPICIOUS — normal_5f886ad231f7e.pdf
SUSPICIOUS — normal_5f886ad231f7e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2ebe3c32a74135764c9b0643d555eba6421ef0ec7194f7fa1ab8a807ea8b562d - SHA-1:
7e61ab8201feed20ebc56effbc10fa9eda8f08df - MD5:
46ae5420af1d8bf2ba563ff74adca9dd - ssdeep:
768:/AgGzpD+pgf84XhDQ+5+h1QJHa+tLREPVTyO0AE/QfyZF+4QR+QnAQ1jkGk3ihOd:VGF6pvutLSPtb0v/0yZxQR+QnAQmGk4S - TLSH:
T14B32AEF75097ED8D3A8E6B03DAA7205D6449C68D6036D66108CC333ED0B86ED7E11AA1 - Submitted as: normal_5f886ad231f7e.pdf
- File type: pdf · Size: 44675 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4365584/normal_5f8707b990cbc.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=best+chinese+translation+app+android, https://uploads.strikinglycdn.com/files/1424d360-7d0a-4d63-8ec2-e0024f8cf8c1/patow.pdf, https://uploads.strikinglycdn.com/files/ef871c8f-e513-4f97-9dec-1909ad89e77a/doxodewev.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=best+chinese+translation+app+android
- https://uploads.strikinglycdn.com/files/1424d360-7d0a-4d63-8ec2-e0024f8cf8c1/patow.pdf
- https://uploads.strikinglycdn.com/files/ef871c8f-e513-4f97-9dec-1909ad89e77a/doxodewev.pdf
- https://uploads.strikinglycdn.com/files/3f0cec61-2eae-464c-a637-bd9e36881d69/19718406777.pdf
- https://uploads.strikinglycdn.com/files/f0cd6a3d-6652-4f0d-9618-664ce88ea13a/1167234725.pdf
- https://uploads.strikinglycdn.com/files/cec7d065-6c54-4467-99a2-d0a47363aa37/semim.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f8707b990cbc.pdf
- https://cdn.shopify.com/s/files/1/0484/1347/4984/files/champaign_county_property_record_search.pdf
- https://cdn.shopify.com/s/files/1/0266/9025/7081/files/walmart_multivitamin_50.pdf
- https://cdn.shopify.com/s/files/1/0492/9047/7724/files/hakanaku_mo_towa_no_kanashi_mp3.pdf
- https://uploads.strikinglycdn.com/files/30b20da6-89c4-4563-b1a1-c225563e7fb9/24028913490.pdf
- https://uploads.strikinglycdn.com/files/d326f58a-8b95-4e13-9dd7-c8aa63491c3a/35807185598.pdf
- https://cdn.shopify.com/s/files/1/0496/6439/3367/files/16570105281.pdf
- https://cdn.shopify.com/s/files/1/0436/8154/6390/files/oracin_para_que_me_busque_inmediatamente.pdf
- https://cdn.shopify.com/s/files/1/0432/2131/9839/files/biological_molecules_video_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0478/0710/3143/files/pedalevaxularaxiga.pdf
- https://cdn.shopify.com/s/files/1/0482/1912/7965/files/xarudetagunoxiluxonatevuv.pdf
- https://cdn.shopify.com/s/files/1/0469/0558/9920/files/stock_tank_heater_solar-powered.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report