SUSPICIOUS — normal_5f893f14cc2d2.pdf
SUSPICIOUS — normal_5f893f14cc2d2.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a0577908f63273f52e8f8c280a1ee56f42b2c5ca6091a925eefdb2bdaab562e0 - SHA-1:
3e2a30345c8021ea2615ed3d12a3a5c43be95643 - MD5:
2aeb44bffe5ab91491100d3413435048 - ssdeep:
1536:3GFApLl66vIqChsDwjo8kY33OYzwiuY9B8yKb:WFApLPvLwE8km+Y0iu0B8d - TLSH:
T14136CFF71097ED8C3ECB6B439AE71975948E968D713697205088773C88BC6EC2E01D92 - Submitted as: normal_5f893f14cc2d2.pdf
- File type: pdf · Size: 65228 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/e786f6bf-8c50-439a-b210-c9af46a3b94f/pufisodurug.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=appraisal+form+sample+pdf, https://jurizimobijagi.weebly.com/uploads/1/3/0/8/130874317/tozob_senetukol_kidek_gatudov.pdf, https://zewubonorow.weebly.com/uploads/1/3/1/3/131398185/xukupidexodiwuwe.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=appraisal+form+sample+pdf
- https://jurizimobijagi.weebly.com/uploads/1/3/0/8/130874317/tozob_senetukol_kidek_gatudov.pdf
- https://zewubonorow.weebly.com/uploads/1/3/1/3/131398185/xukupidexodiwuwe.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/mozaxiwafifusobeji.pdf
- https://kabudededawizo.weebly.com/uploads/1/3/1/3/131383409/8644275.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/zakeme.pdf
- https://uploads.strikinglycdn.com/files/e786f6bf-8c50-439a-b210-c9af46a3b94f/pufisodurug.pdf
- https://uploads.strikinglycdn.com/files/b42362cf-4301-4b49-bf99-1df37c987717/69997036012.pdf
- https://uploads.strikinglycdn.com/files/40227df4-effe-42b1-a2e5-4642ab336129/silusalak.pdf
- https://uploads.strikinglycdn.com/files/be9d38a9-6044-40ec-aeeb-7f897764b536/meroriborisixebat.pdf
- https://uploads.strikinglycdn.com/files/6f7ed849-332d-4a9f-9942-db2255518e3e/redowigefadox.pdf
- https://uploads.strikinglycdn.com/files/198e3880-b5e4-4050-9535-5096123793d7/71003637107.pdf
- https://uploads.strikinglycdn.com/files/e857817c-cb05-42cf-924e-624f66dd37b6/77991625267.pdf
- https://uploads.strikinglycdn.com/files/7f5ebb63-29dd-40ab-8f4a-1dc44c795b32/xefopiripuke.pdf
- https://uploads.strikinglycdn.com/files/7399f1bf-5444-477d-841c-59c20274773f/bubotum.pdf
- https://uploads.strikinglycdn.com/files/e4c5d0db-c74f-4768-8d0a-c174b2da5949/rukopidadiv.pdf
- https://uploads.strikinglycdn.com/files/592097f2-b4f1-404d-8545-e271eb118ef5/megonovatuxigojupi.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/8536469.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tifuxasorelav-sunagutigu-gikisifexixabot.pdf
- https://wivupenoremew.weebly.com/uploads/1/3/0/7/130775018/199e184b.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f89379fb7316.pdf
- https://cdn-cms.f-static.net/uploads/4374203/normal_5f88f6ea614ef.pdf
- https://cdn-cms.f-static.net/uploads/4366024/normal_5f873d1e014db.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- jurizimobijagi.weebly.com
- zewubonorow.weebly.com
- juragubiv.weebly.com
- kabudededawizo.weebly.com
- dimaxafazeza.weebly.com
- uploads.strikinglycdn.com
- jakedekokobara.weebly.com
- genigudepa.weebly.com
- wivupenoremew.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report