SUSPICIOUS — normal_5f877d3e8f94e.pdf
SUSPICIOUS — normal_5f877d3e8f94e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6d58823d7f88c5760c2a2946a997b243c9cf92ad82d2ad88727fe76498efabdc - SHA-1:
7fb57f95baafeb0d76e87630fc6fdae5d507ea32 - MD5:
07ebf4a6624d60dc1e5781d65820646c - ssdeep:
768:AgGzpDMpDQN4zf7OVzHFo1JfFEfjOUk8HDDMy0h12D4O4g29a+C7:NGFgpDZqgFEOd8cyK2D4O4g/+C7 - TLSH:
T175327CF35093ED4C7A8EAB07AEEB00A8908DC68D5136D79054CC672DD47CAED2F10A65 - Submitted as: normal_5f877d3e8f94e.pdf
- File type: pdf · Size: 43622 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3925716f-843f-4233-b5e5-ce3f63370311/gixemanulivan.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=descargar+photoshop+apk+full+gratis, https://cdn-cms.f-static.net/uploads/4366665/normal_5f876739da069.pdf, https://cdn-cms.f-static.net/uploads/4365539/normal_5f87026b26fc1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=descargar+photoshop+apk+full+gratis
- https://cdn-cms.f-static.net/uploads/4366665/normal_5f876739da069.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f87026b26fc1.pdf
- https://cdn-cms.f-static.net/uploads/4366011/normal_5f870f80a7f94.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f872b1e9ae03.pdf
- https://uploads.strikinglycdn.com/files/3925716f-843f-4233-b5e5-ce3f63370311/gixemanulivan.pdf
- https://uploads.strikinglycdn.com/files/67c882e0-3dd5-49b6-a2b1-ccc0292569c7/nolupat.pdf
- https://uploads.strikinglycdn.com/files/6e2900e5-d21a-44a8-b2ec-5faa7e327bc8/55993001658.pdf
- https://uploads.strikinglycdn.com/files/c777cb03-4a51-4395-86ec-f1be8d699e4e/74054603722.pdf
- https://uploads.strikinglycdn.com/files/abd85dca-1c86-49b3-bd29-fcd4918ec89d/14748657205.pdf
- https://uploads.strikinglycdn.com/files/246bc8b0-167b-449c-b531-d5382b729957/vofuj.pdf
- https://cdn.shopify.com/s/files/1/0486/2630/3136/files/98911393732.pdf
- https://cdn.shopify.com/s/files/1/0486/2613/9294/files/83499557453.pdf
- https://cdn.shopify.com/s/files/1/0495/5435/8439/files/zigazexokejeja.pdf
- https://cdn.shopify.com/s/files/1/0436/9799/5941/files/bubble_letter_heart_font.pdf
- https://cdn.shopify.com/s/files/1/0439/1141/3915/files/dark_phoenix_costume.pdf
- https://uploads.strikinglycdn.com/files/a486ce9d-62d3-4ef1-9fe1-7c07ae7ef124/93089010929.pdf
- https://uploads.strikinglycdn.com/files/ac20452c-ed32-4d95-a111-a9b1baabce0d/gizujetisine.pdf
- https://uploads.strikinglycdn.com/files/bfb63e25-27e3-4174-9ac8-5bbdf93af003/vivupesuxonapoxef.pdf
- https://uploads.strikinglycdn.com/files/5a77c154-cb60-4527-aa2e-7b661a503cac/vevuzafi.pdf
- https://uploads.strikinglycdn.com/files/542655bd-7243-4f6e-9c8f-1b60f2a86f80/bixomapaj.pdf
- https://site-1040249.mozfiles.com/files/1040249/22616882296.pdf
- https://site-1044159.mozfiles.com/files/1044159/48896352047.pdf
- https://site-1042286.mozfiles.com/files/1042286/padivegupixukugigemu.pdf
- https://site-1042585.mozfiles.com/files/1042585/xedimazanemobifememagaso.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1040249.mozfiles.com
- site-1044159.mozfiles.com
- site-1042286.mozfiles.com
- site-1042585.mozfiles.com
- site-1039513.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report