SUSPICIOUS — bartaman_bengali_newspaper.pdf
SUSPICIOUS — bartaman_bengali_newspaper.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3a6e1734b7a23fa6c6865b5cfa9617633cf1634348c048d3d21afb287c7fef31 - SHA-1:
53731b3871723e98d064046186da75f88d6b37df - MD5:
0c1da6eeae7e011b38ee39afcc4347c2 - ssdeep:
768:5gGzpDvgpACiKZL27L6YHljNMeL640jbXb40r8k5F8NrHcBQQaSJDIWELt1wwRRd:6GFcpAt8O6Hxr5daUiVvjRRvpN/C/uyU - TLSH:
T143328DF75497DD8C7ACAAB43ECAB11A6618EC34861369B6045DC362CC4BC2FD6E10D60 - Submitted as: bartaman_bengali_newspaper.pdf
- File type: pdf · Size: 46236 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ccf11cde-77fb-418b-a9ca-87404f6925a8/46475376563.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=bartaman+bengali+newspaper+pdf, https://cdn-cms.f-static.net/uploads/4384825/normal_5f8d20278ffad.pdf, https://cdn-cms.f-static.net/uploads/4373998/normal_5f890bae08920.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=bartaman+bengali+newspaper+pdf
- https://cdn-cms.f-static.net/uploads/4384825/normal_5f8d20278ffad.pdf
- https://cdn-cms.f-static.net/uploads/4373998/normal_5f890bae08920.pdf
- https://cdn-cms.f-static.net/uploads/4368772/normal_5f8bc578950f1.pdf
- https://uploads.strikinglycdn.com/files/ccf11cde-77fb-418b-a9ca-87404f6925a8/46475376563.pdf
- https://uploads.strikinglycdn.com/files/9b6fb236-0659-4e2c-936e-7889540e10db/franklin_covey_planner_templates_dow.pdf
- https://uploads.strikinglycdn.com/files/073bae62-e089-4c1f-972d-724adf018983/tesaxujaziwixarudegemefi.pdf
- https://uploads.strikinglycdn.com/files/65ddbce4-5e2d-4ddb-a238-2e55dbc062b9/setazuzewovi.pdf
- https://uploads.strikinglycdn.com/files/f9dfc43b-48ed-4292-a4c2-77b0fc444aae/jejafusofobijubisudumabo.pdf
- https://mogilifus.weebly.com/uploads/1/3/0/7/130739831/bosilo_ginasesif.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/tuberokaxe.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/wotagajinobuful.pdf
- https://jopalezaleloloj.weebly.com/uploads/1/3/1/3/131380469/1f9b4bef89.pdf
- https://cdn-cms.f-static.net/uploads/4367645/normal_5f87dd256a7e3.pdf
- https://cdn-cms.f-static.net/uploads/4368503/normal_5f8ae5f9aa2cc.pdf
- https://cdn-cms.f-static.net/uploads/4381544/normal_5f8b66ff23264.pdf
- https://cdn-cms.f-static.net/uploads/4368225/normal_5f88a09e612a0.pdf
- https://uploads.strikinglycdn.com/files/df4daa36-6466-4df4-996f-b86df52e46d4/90886710462.pdf
- https://uploads.strikinglycdn.com/files/19b12840-bf22-4c80-8e02-095e57382cca/ovlda_hp_deskjet_3650_zadarmo.pdf
- https://uploads.strikinglycdn.com/files/96fbfc26-4f2e-4ed3-94c7-11df4017131a/fewub.pdf
- https://uploads.strikinglycdn.com/files/47a39ce7-42c3-407f-be55-8f2a856b8b7c/58386755003.pdf
- https://uploads.strikinglycdn.com/files/b5b979b5-5f2c-4a34-b8a4-dab16bcfaa3d/4012198965.pdf
- https://texitanoz.weebly.com/uploads/1/3/0/7/130739996/mijiku.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/3ffb8050303ca.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- mogilifus.weebly.com
- babikovinemixe.weebly.com
- pigogokeda.weebly.com
- jopalezaleloloj.weebly.com
- texitanoz.weebly.com
- saxibodusazo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report