SUSPICIOUS — normal_5f87139addce6.pdf
SUSPICIOUS — normal_5f87139addce6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
74616fdd257adcf7022bc23ed97b8a81f860cf96f5876b8497c66ec0a1b838e9 - SHA-1:
cf517a85d872c7339fea76716d2622940adb5618 - MD5:
e3962f6ceb49d854009d4359ee22a39b - ssdeep:
768:pgGzpDqpmUyeXCeuugHecMKM1n3BiH0bCRXzK6L5nRD2rP22N6K4E:KGFWpxXKuQNrtRCKK4E - TLSH:
T168318DF320A7DD4C7A8FAF13ADA71198A18FD7896132A760048C672CD0BC6ED2E11911 - Submitted as: normal_5f87139addce6.pdf
- File type: pdf · Size: 42234 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3775e91f-76f7-4b56-85b1-9e1e86faea69/33899077658.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=history+of+football+in+the+world+pdf, https://cdn-cms.f-static.net/uploads/4365653/normal_5f8704db3b79d.pdf, https://cdn-cms.f-static.net/uploads/4366031/normal_5f870a52a8d43.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=history+of+football+in+the+world+pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f8704db3b79d.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f870a52a8d43.pdf
- https://cdn-cms.f-static.net/uploads/4365575/normal_5f87096c3b069.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f8712ee99045.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f86fc3212911.pdf
- https://uploads.strikinglycdn.com/files/da24d952-fd73-4ece-b382-aa169a9b693d/57249895231.pdf
- https://uploads.strikinglycdn.com/files/ed7a721d-44e1-4b58-860e-e486ae6c81c6/21999163819.pdf
- https://uploads.strikinglycdn.com/files/3775e91f-76f7-4b56-85b1-9e1e86faea69/33899077658.pdf
- https://cdn-cms.f-static.net/uploads/4366020/normal_5f86fafc4399b.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f86f47359702.pdf
- https://cdn-cms.f-static.net/uploads/4365549/normal_5f86f493d1ecb.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f870a520a0ac.pdf
- https://site-1038995.mozfiles.com/files/1038995/pemuvumazenavufib.pdf
- https://site-1038520.mozfiles.com/files/1038520/vidifasufalixewigo.pdf
- https://site-1036803.mozfiles.com/files/1036803/velojiwiro.pdf
- https://site-1036796.mozfiles.com/files/1036796/putisetimimodej.pdf
- https://uploads.strikinglycdn.com/files/1ffd4192-c402-4d04-8024-8abd094773ff/jewubomin.pdf
- https://uploads.strikinglycdn.com/files/ee28f9b6-a8e6-4bf1-8c27-5f12a84da6cf/daxatufetasufexutokame.pdf
- https://uploads.strikinglycdn.com/files/0d474807-5504-4694-9edf-abe1ae3861bf/lumekagagikajexitewu.pdf
- https://uploads.strikinglycdn.com/files/55a928d8-cd1d-40ff-801b-bbea53f8b5fb/wozuzinunipovuk.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f8704b3f0cd8.pdf
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f8709f71a2aa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038995.mozfiles.com
- site-1038520.mozfiles.com
- site-1036803.mozfiles.com
- site-1036796.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report