SUSPICIOUS — normal_5f87608c48168.pdf
SUSPICIOUS — normal_5f87608c48168.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8a1ecd186aeafb0637dcf43c47500d22aa22219951a011ae265d385be3010985 - SHA-1:
f1e5d3e069ffe08718815e6598af9fb81d7e61a3 - MD5:
c11bc68a810c9c13fad65ec70907519e - ssdeep:
768:xgGzpDlp4Y1zRta1KjwG9PuqxthM99KO/JzABYNtQeN8pHf4ftAIBOjLZYQ:CGFBplxthM9j/JABHXHf9ICLZYQ - TLSH:
T1FC329DF31497ED8C7A8BAB035CA71465A08AC7892137DB90559C3B2CC5BC6BC7F10A61 - Submitted as: normal_5f87608c48168.pdf
- File type: pdf · Size: 45015 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4365627/normal_5f870000614bc.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=tamil+pdf+novels+free, https://cdn-cms.f-static.net/uploads/4365627/normal_5f870000614bc.pdf, https://cdn-cms.f-static.net/uploads/4367940/normal_5f875ae981692.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=tamil+pdf+novels+free
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f870000614bc.pdf
- https://cdn-cms.f-static.net/uploads/4367940/normal_5f875ae981692.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f86f8e275b7b.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f87199501de1.pdf
- https://cdn.shopify.com/s/files/1/0429/3689/3599/files/zewipurevonebajesi.pdf
- https://cdn.shopify.com/s/files/1/0486/0484/0096/files/compare_and_contrast_two_paintings_essay.pdf
- https://cdn.shopify.com/s/files/1/0498/5549/6347/files/83515889304.pdf
- https://cdn.shopify.com/s/files/1/0440/2728/1558/files/ragobivogovutifajagotirol.pdf
- https://site-1044294.mozfiles.com/files/1044294/55523723172.pdf
- https://site-1039672.mozfiles.com/files/1039672/19522337229.pdf
- https://site-1037905.mozfiles.com/files/1037905/67402901249.pdf
- https://uploads.strikinglycdn.com/files/5ba925f8-fafd-4d8b-a1bb-5f7bfda1d1cb/dasigadedivalumabuvuwis.pdf
- https://uploads.strikinglycdn.com/files/76b18015-ca55-49a2-892b-0653bb1e3fcc/lofalagojaxe.pdf
- https://uploads.strikinglycdn.com/files/76f6ca02-2673-41e3-a8fc-5abde80ad41d/52535590395.pdf
- https://uploads.strikinglycdn.com/files/db7a9bc6-564e-4ed2-9ce4-9b47c88049c3/38778226443.pdf
- https://cdn-cms.f-static.net/uploads/4367310/normal_5f874b6eb3105.pdf
- https://cdn-cms.f-static.net/uploads/4366022/normal_5f86f92e98311.pdf
- https://uploads.strikinglycdn.com/files/b4894cd2-5022-4482-9c63-d96cfd3720c8/wapodujodagebuja.pdf
- https://uploads.strikinglycdn.com/files/2e7c99c2-a0b7-4836-9660-6ff2a5dcaacd/24870617304.pdf
- https://uploads.strikinglycdn.com/files/6705681f-5e4a-44cc-a8df-6a83a2bdb1f3/59251268815.pdf
- https://uploads.strikinglycdn.com/files/974b1f0c-f3a8-4eb8-b35c-7d34d74e730c/58694628742.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1044294.mozfiles.com
- site-1039672.mozfiles.com
- site-1037905.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report