SUSPICIOUS — normal_5f88079443552.pdf
SUSPICIOUS — normal_5f88079443552.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2f82a8ef951d347f38fcd69ed590d35e1af3c29dff704270ac410428722d39be - SHA-1:
58a3778e0f46e56f3dc5dddd699c6cbe30da173b - MD5:
bfe752717ba89d13f5ab99e1e2702d30 - ssdeep:
768:wgGzpDApIGasSC2PGQ3oTz9IQRyURAYjQ4+76Zcq1velms+rGkrzrCA:dGF0pusSQpIQBXs4+2i6P7yk3eA - TLSH:
T1CF33AFF350A7ED8CBA89BF47ADBB1119604AD68D6033A7501488673DC47CAFDAF00961 - Submitted as: normal_5f88079443552.pdf
- File type: pdf · Size: 47780 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9e8cf668-7d67-44e3-81e1-4b78ca331438/xefamituniw.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=food+chain+pictures+pdf, https://uploads.strikinglycdn.com/files/9e8cf668-7d67-44e3-81e1-4b78ca331438/xefamituniw.pdf, https://uploads.strikinglycdn.com/files/365d26ce-5f7b-44bd-833b-55a79ca5e78f/winabupemazevodom.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=food+chain+pictures+pdf
- https://uploads.strikinglycdn.com/files/9e8cf668-7d67-44e3-81e1-4b78ca331438/xefamituniw.pdf
- https://uploads.strikinglycdn.com/files/365d26ce-5f7b-44bd-833b-55a79ca5e78f/winabupemazevodom.pdf
- https://uploads.strikinglycdn.com/files/e7df0c16-b293-4642-afe0-21884ddfcff0/puzudukebupuzimeburub.pdf
- https://uploads.strikinglycdn.com/files/d6ca3aa3-d8f1-46f6-a5be-4bb47300ea32/28454440411.pdf
- https://uploads.strikinglycdn.com/files/8711b003-c444-45ff-97be-b733411f283f/sevutu.pdf
- https://site-1038920.mozfiles.com/files/1038920/71700083315.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/mezevoxinokimuwamibu.pdf
- https://jiwepurojal.weebly.com/uploads/1/3/0/7/130775762/5397186.pdf
- https://zulatikuwa.weebly.com/uploads/1/3/0/7/130776211/razisepijelus.pdf
- https://wefamojugibe.weebly.com/uploads/1/3/1/1/131164519/dd9033d67f05d8.pdf
- https://uploads.strikinglycdn.com/files/0d9d30c8-6f0e-44c5-8756-effbb5826063/gubesusijuwusul.pdf
- https://uploads.strikinglycdn.com/files/c8854824-d782-45e8-a594-b1757533690b/tefetuvarufu.pdf
- https://uploads.strikinglycdn.com/files/c493fd6f-b636-48dc-aff6-019da13752a2/dipesik.pdf
- https://uploads.strikinglycdn.com/files/654c9eff-eb52-4898-ac19-fbd619fb4d6c/6599194772.pdf
- https://uploads.strikinglycdn.com/files/c52a844e-a3de-4a74-afb8-ba50a42e2643/neninakes.pdf
- https://uploads.strikinglycdn.com/files/7f458c50-beeb-4370-9266-456f06b77da0/valenalabiget.pdf
- https://site-1038898.mozfiles.com/files/1038898/53768906869.pdf
- https://site-1038338.mozfiles.com/files/1038338/73863797990.pdf
- https://site-1040249.mozfiles.com/files/1040249/18993193760.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1038920.mozfiles.com
- xojerajap.weebly.com
- jiwepurojal.weebly.com
- zulatikuwa.weebly.com
- wefamojugibe.weebly.com
- site-1038898.mozfiles.com
- site-1038338.mozfiles.com
- site-1040249.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report