SUSPICIOUS — normal_5f8afa2b88049.pdf
SUSPICIOUS — normal_5f8afa2b88049.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8d2d69d0000d1ecb30a630a784f3371c1c962018c150f1f11d9bc23a19d68de6 - SHA-1:
4f62e6f93710c4e8073ea6cb155381734a19c6aa - MD5:
2339434bc2dc9584432bd194ed0aa0d8 - ssdeep:
768:bgGzpD2pX8V69YqhRrqQYZFJmxjCKk4FFyF9kHe72TV2ZN2gaGlOm0+txfi:kGFypXEUjZJIFzUVFGlOm0+bfi - TLSH:
T1B6329DF71497DE4D7A8BDB436DEA24256149CB8C7636D76009C8772CC8BC6BDAE00860 - Submitted as: normal_5f8afa2b88049.pdf
- File type: pdf · Size: 44733 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4376358/normal_5f89cabea05bc.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=new+jersey+sales+%2526+use+tax+guide, https://cdn-cms.f-static.net/uploads/4371265/normal_5f88c07dc2ae1.pdf, https://cdn-cms.f-static.net/uploads/4376358/normal_5f89cabea05bc.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=new+jersey+sales+%2526+use+tax+guide
- https://cdn-cms.f-static.net/uploads/4371265/normal_5f88c07dc2ae1.pdf
- https://cdn-cms.f-static.net/uploads/4376358/normal_5f89cabea05bc.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f8750164e8d0.pdf
- https://cdn.shopify.com/s/files/1/0496/7451/8691/files/virtual_beggar_time_glitch.pdf
- https://cdn.shopify.com/s/files/1/0495/5255/6184/files/download_font_for_android_phone_free.pdf
- https://cdn.shopify.com/s/files/1/0497/9346/6521/files/40936425883.pdf
- https://cdn.shopify.com/s/files/1/0496/2412/1495/files/samidumemotowexulosopat.pdf
- https://cdn-cms.f-static.net/uploads/4369315/normal_5f87fa0519879.pdf
- https://cdn-cms.f-static.net/uploads/4366321/normal_5f8874d113e6d.pdf
- https://cdn-cms.f-static.net/uploads/4371497/normal_5f8908997b9f6.pdf
- https://uploads.strikinglycdn.com/files/c566ae5b-3fad-4693-9a5d-073b0e9e7b0a/50291052845.pdf
- https://uploads.strikinglycdn.com/files/eaef26f5-db2b-4e77-ac14-07f1183f4c96/mopunumuzazop.pdf
- https://uploads.strikinglycdn.com/files/de37568b-a0db-4d15-9bcd-f902a1b871ee/65471675521.pdf
- https://tegugozitofo.weebly.com/uploads/1/3/0/8/130874592/815444.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/lekov.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/9594994.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/a63fb.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tadib-pepalitegugoj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- tegugozitofo.weebly.com
- rabifupokuwu.weebly.com
- mojivimimujovo.weebly.com
- jatorogerujew.weebly.com
- genigudepa.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report