SUSPICIOUS — normal_5f89461ba5d43.pdf
SUSPICIOUS — normal_5f89461ba5d43.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
92c4a4a1af0f130d7232f174645aca85c7d86f9944942a5c6f9d95bb3e3669b7 - SHA-1:
285dec5aa4ba5c49d5c6fcda782dd991e77352fc - MD5:
9f3966c7e9444367ae7c881288cdff65 - ssdeep:
768:Mq0gGzpDgpQzHnx0GfJtutSB9Va9ck56O4mKhyqPaTGkgVt1fLnjG3D2mLX0N3nP:XBGF8pQsN63CykgfJnjmKmrErQwSCkyf - TLSH:
T19D327DF310A3FC8D3A8A9F07ADBB015EA189D68D6123965004CC761CE4BC6FE7E10661 - Submitted as: normal_5f89461ba5d43.pdf
- File type: pdf · Size: 44495 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/2f1d277d-0406-4a67-8666-5e125e9c59f8/rolivexoti.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=file+manager+for+android+2.3.7, https://cdn.shopify.com/s/files/1/0502/9416/1605/files/case_study_on_rainwater_harvesting.pdf, https://cdn.shopify.com/s/files/1/0437/7424/7069/files/tenitinuvumanutulofut.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=file+manager+for+android+2.3.7
- https://cdn.shopify.com/s/files/1/0502/9416/1605/files/case_study_on_rainwater_harvesting.pdf
- https://cdn.shopify.com/s/files/1/0437/7424/7069/files/tenitinuvumanutulofut.pdf
- https://cdn.shopify.com/s/files/1/0430/3876/9303/files/hkcee_physics_mc_answer.pdf
- https://cdn.shopify.com/s/files/1/0429/9456/5271/files/at_the_cross_hillsong_chords.pdf
- https://cdn.shopify.com/s/files/1/0484/8281/2066/files/89050359834.pdf
- https://cdn.shopify.com/s/files/1/0486/1162/3072/files/42880924500.pdf
- https://cdn.shopify.com/s/files/1/0266/8586/6167/files/85559870817.pdf
- https://cdn.shopify.com/s/files/1/0482/7224/4900/files/stickman_torture_game_unblocked.pdf
- https://cdn.shopify.com/s/files/1/0483/5901/4551/files/vatiwowijelodesikurexa.pdf
- https://cdn.shopify.com/s/files/1/0479/2785/3223/files/81683693508.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/wovexofek.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/914e7258.pdf
- https://topodomero.weebly.com/uploads/1/3/2/6/132696018/ea11310661c.pdf
- https://uploads.strikinglycdn.com/files/2f1d277d-0406-4a67-8666-5e125e9c59f8/rolivexoti.pdf
- https://uploads.strikinglycdn.com/files/e97a8aae-6964-4a26-ba37-ed769982d46d/95821268218.pdf
- https://uploads.strikinglycdn.com/files/b3985757-e605-47f4-8d5a-af3b66fb4836/85647281694.pdf
- https://cdn.shopify.com/s/files/1/0500/1075/1126/files/maths_question_bank_class_12.pdf
- https://cdn.shopify.com/s/files/1/0497/2940/5108/files/sedowajokuge.pdf
- https://cdn.shopify.com/s/files/1/0497/3215/7601/files/georgia_state_medical_board_disciplinary_actions.pdf
- https://cdn.shopify.com/s/files/1/0486/5979/2022/files/shaded_area_circles_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0438/6285/1749/files/touch_of_eco_suntrap_pro_review.pdf
- https://cdn.shopify.com/s/files/1/0438/3516/2784/files/7670471705.pdf
- https://cdn.shopify.com/s/files/1/0435/9746/3714/files/navana.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- jawasolasazilem.weebly.com
- nobinetezo.weebly.com
- topodomero.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report