SUSPICIOUS — normal_5f89666fada8c.pdf
SUSPICIOUS — normal_5f89666fada8c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8b82605bfe80545848a049d5548e7c720a03909d307f9c13190b1d72d2e24e84 - SHA-1:
da63717a50e02f62f729320c96e3f43a958ec525 - MD5:
02ffe35e7787b867c4281a420eeeb2a2 - ssdeep:
768:odgGzpD7pXFfbKCZ3FuMJ/VUeLJBV6xQMTuz6BrO6Zoe8J7hWcM1Sqx+tfORG0z1:rGFnpXIQnkO6u97u1SqxD7zWF2ELW - TLSH:
T158329EF32057EDCD7A8A5B076F6B041AA48AC28C6036D79154CC772CC6BC5FD5E10A62 - Submitted as: normal_5f89666fada8c.pdf
- File type: pdf · Size: 43594 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c03a01eb-7c24-4c6c-a719-3be7503ee789/10863394855.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=best+offline+dictionary+for+android+download, https://cdn.shopify.com/s/files/1/0431/6590/9143/files/debawifumexa.pdf, https://cdn.shopify.com/s/files/1/0438/3594/9218/files/planner_2019_to_2020.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=best+offline+dictionary+for+android+download
- https://cdn.shopify.com/s/files/1/0431/6590/9143/files/debawifumexa.pdf
- https://cdn.shopify.com/s/files/1/0438/3594/9218/files/planner_2019_to_2020.pdf
- https://cdn.shopify.com/s/files/1/0500/0996/4735/files/98662174988.pdf
- https://uploads.strikinglycdn.com/files/c03a01eb-7c24-4c6c-a719-3be7503ee789/10863394855.pdf
- https://uploads.strikinglycdn.com/files/28e5ac79-d3db-45a4-81de-3deb4d2aba2f/zawixixefukunevotorepoxit.pdf
- https://uploads.strikinglycdn.com/files/c4c337d1-97f9-40bb-b52d-74a89574b42b/54735478140.pdf
- https://cdn.shopify.com/s/files/1/0485/8521/2064/files/20687141471.pdf
- https://cdn.shopify.com/s/files/1/0435/0240/3750/files/jizopenovexunexujawexowu.pdf
- https://cdn.shopify.com/s/files/1/0434/4178/2946/files/jofuzeganirojorajusa.pdf
- https://cdn.shopify.com/s/files/1/0496/0662/3384/files/pewufiwereribitidu.pdf
- https://cdn.shopify.com/s/files/1/0433/6346/7414/files/canaan_elementary_school_calendar.pdf
- https://cdn.shopify.com/s/files/1/0497/3586/0378/files/mowepapimezulijavepexe.pdf
- https://cdn.shopify.com/s/files/1/0480/1239/4649/files/47389534893.pdf
- https://cdn.shopify.com/s/files/1/0438/7779/3960/files/creative_illustrations_studio.pdf
- https://cdn-cms.f-static.net/uploads/4370062/normal_5f890b7f837aa.pdf
- https://cdn-cms.f-static.net/uploads/4369150/normal_5f890812cd632.pdf
- https://cdn-cms.f-static.net/uploads/4372080/normal_5f88bad26c52d.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f87e550a7816.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report