SUSPICIOUS — normal_5f872d6433f06.pdf
SUSPICIOUS — normal_5f872d6433f06.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a295c6026fb32dd5972b7712c2ec535665075b990bda61c8357fbd58e79806b4 - SHA-1:
a459259eeb5e8dd38cae8a9ce87a1d1eae044ef9 - MD5:
f55ee8eb624939d73b6041274ac3ee7f - ssdeep:
768:DWRgGzpDyptkrfSfh2VgnI6gRbG6dYS0YPKILwXvCuRrQWO/s5gd6YAbdgWMxP4:5GF+ptigiG6SFgw9os5gabidxP4 - TLSH:
T1E0328DF35167ED4C798AEB136EFA21AC444AE78C50329B645588672CC4BC3BD7F40A60 - Submitted as: normal_5f872d6433f06.pdf
- File type: pdf · Size: 47147 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3b09e297-63df-4522-8ec4-b08e95bf813b/xazavurotukujujigavefuzin.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=leap+motion+connect+android, https://cdn-cms.f-static.net/uploads/4366339/normal_5f871529cf74b.pdf, https://cdn-cms.f-static.net/uploads/4365553/normal_5f870661aa602.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=leap+motion+connect+android
- https://cdn-cms.f-static.net/uploads/4366339/normal_5f871529cf74b.pdf
- https://cdn-cms.f-static.net/uploads/4365553/normal_5f870661aa602.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f8714b7e29b2.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f86f534261d8.pdf
- https://uploads.strikinglycdn.com/files/3b09e297-63df-4522-8ec4-b08e95bf813b/xazavurotukujujigavefuzin.pdf
- https://uploads.strikinglycdn.com/files/8d323fe1-db51-4ee7-9e83-1090049bc682/84874497687.pdf
- https://uploads.strikinglycdn.com/files/c702efac-5759-4690-a186-2109d1f993c1/nawuxevirideselo.pdf
- https://uploads.strikinglycdn.com/files/e24afc7d-5e1e-4d4c-8fc6-f9df63637c1b/41980681339.pdf
- https://uploads.strikinglycdn.com/files/61862516-2aab-45d3-8366-dd5b29d11f65/32309806100.pdf
- https://uploads.strikinglycdn.com/files/69e9ac5d-8751-45ef-9ed1-41b3eb4f9f44/kimerep.pdf
- https://site-1037267.mozfiles.com/files/1037267/romoridoxujoloxetako.pdf
- https://site-1048190.mozfiles.com/files/1048190/piturozilobe.pdf
- https://site-1039689.mozfiles.com/files/1039689/patokidod.pdf
- https://site-1040284.mozfiles.com/files/1040284/visisaxuxonafukux.pdf
- https://site-1039967.mozfiles.com/files/1039967/84165877344.pdf
- https://uploads.strikinglycdn.com/files/69637402-c46c-40b8-b44f-554017de839e/bivax.pdf
- https://uploads.strikinglycdn.com/files/31b0672b-a60b-45c4-817a-d7915dc5c22d/75945600976.pdf
- https://uploads.strikinglycdn.com/files/5817b59c-7099-4b57-88f3-6444dd1cd58f/71313655246.pdf
- https://cdn-cms.f-static.net/uploads/4366348/normal_5f870ea7498a3.pdf
- https://cdn-cms.f-static.net/uploads/4365583/normal_5f870660c58f7.pdf
- https://cdn-cms.f-static.net/uploads/4365567/normal_5f8709e4eec1b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1037267.mozfiles.com
- site-1048190.mozfiles.com
- site-1039689.mozfiles.com
- site-1040284.mozfiles.com
- site-1039967.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report