SUSPICIOUS — normal_5f87a76d5c4c8.pdf
SUSPICIOUS — normal_5f87a76d5c4c8.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
988fb8bf2962387dd9d9a3e4cd7c816dca54b49d1aaa6d177937ce7f698d0616 - SHA-1:
d2a3046ff06201624940329761895641c71eea03 - MD5:
b18ffa166a237d9718532ef753c8fa1b - ssdeep:
1536:jGFQpNGoIc8TiZipIJjcqvHmd+bIHft6JPCowjEX7:yFQpEoIc87IJdvHmdOoftOPCowW - TLSH:
T11934AEF31197ED8C3B8BAB07ADB60158548AD388717697B041882B7CC47C6FEBE44A51 - Submitted as: normal_5f87a76d5c4c8.pdf
- File type: pdf · Size: 55793 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6b2fdc84-837e-4762-888d-cacc186c6d2f/jaxuzo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=aptransco+syllabus+2020+pdf, https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/xovilefuladoku.pdf, https://jedarixires.weebly.com/uploads/1/3/0/9/130969076/7069695.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=aptransco+syllabus+2020+pdf
- https://nanorobudilason.weebly.com/uploads/1/3/0/7/130775181/xovilefuladoku.pdf
- https://jedarixires.weebly.com/uploads/1/3/0/9/130969076/7069695.pdf
- https://dotofinadi.weebly.com/uploads/1/3/0/7/130740455/luwotebobolobun-repugose.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f879d56e8c12.pdf
- https://cdn-cms.f-static.net/uploads/4368228/normal_5f877a51af7aa.pdf
- https://cdn-cms.f-static.net/uploads/4366947/normal_5f8751aa37682.pdf
- https://cdn.shopify.com/s/files/1/0484/0161/2968/files/pho_777_menu_reno.pdf
- https://cdn.shopify.com/s/files/1/0427/7246/3772/files/balance_scale_equations_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0498/0313/3090/files/west_lyon_football_ranking.pdf
- https://cdn.shopify.com/s/files/1/0484/9162/6657/files/11896893806.pdf
- https://cdn.shopify.com/s/files/1/0487/9876/1125/files/solve_the_two_step_equations_integers.pdf
- https://cdn.shopify.com/s/files/1/0433/1362/7294/files/nathan_the_wise_quotes.pdf
- https://cdn.shopify.com/s/files/1/0434/3290/2806/files/nba_live_mobile_cheats_apk.pdf
- https://site-1037033.mozfiles.com/files/1037033/83598246954.pdf
- https://site-1043170.mozfiles.com/files/1043170/nezubiwuwobelabun.pdf
- https://site-1043650.mozfiles.com/files/1043650/boduxapuwevaligivopili.pdf
- https://uploads.strikinglycdn.com/files/6b2fdc84-837e-4762-888d-cacc186c6d2f/jaxuzo.pdf
- https://uploads.strikinglycdn.com/files/1b0d0867-6f9c-4f25-8c00-454f0b7f4591/kanelesupuluvaxafiriz.pdf
- https://uploads.strikinglycdn.com/files/3f6651a1-58e5-47b4-9138-91e52eb981c2/nefedowerifavadado.pdf
- https://uploads.strikinglycdn.com/files/48df1123-8bbf-4e8d-a939-5462646e31b0/nasibitun.pdf
- https://uploads.strikinglycdn.com/files/718f10b3-fb4e-4c33-92ad-da8234cfa23a/jetemiwijoworeb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- nanorobudilason.weebly.com
- jedarixires.weebly.com
- dotofinadi.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1037033.mozfiles.com
- site-1043170.mozfiles.com
- site-1043650.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report