SUSPICIOUS — normal_5f895a4f50a17.pdf
SUSPICIOUS — normal_5f895a4f50a17.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a71f1a5a2a39d9d05ba9e22c0cee0a6041635dae8db4c72d22b9b628bb535a76 - SHA-1:
48c7161aa86e544fe23bc2e03a9e99b6735c37ca - MD5:
b0c958068a3d5fe28106c9cccc230499 - ssdeep:
768:JgGzpD3pmhg3TnGeckzsGwrtB7Nu34wEQC0x2Ern0GBqJ5bxa:qGF7pmhgDnBcFd1wLx2Er7BSbxa - TLSH:
T17A328DF350EBEC8C7B8B6B43ADA611A9540AD74D61369790558C3B2C84BC6FD7E00B50 - Submitted as: normal_5f895a4f50a17.pdf
- File type: pdf · Size: 45859 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/ca7a982f-f7b0-4200-92de-e6fcd65da18d/34663741604.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=nikon+z7+user+manual, https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/c558058877e76a9.pdf, https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/gupilogipupagip-joreku-juferagod-favovijodaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=nikon+z7+user+manual
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/c558058877e76a9.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/gupilogipupagip-joreku-juferagod-favovijodaf.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/cc0b5212d.pdf
- https://nudojafobedem.weebly.com/uploads/1/3/1/3/131379550/dufes.pdf
- https://uploads.strikinglycdn.com/files/4a9af97d-333a-4e90-aa17-7cdb9c1b14a4/zivaxegaripupesifimik.pdf
- https://uploads.strikinglycdn.com/files/76d0d64b-bb4e-4fd8-b757-520c3b4fffaf/34800702984.pdf
- https://uploads.strikinglycdn.com/files/b4d2a747-5b24-49ec-b28d-f842b185a27a/wibojosotolelovovuwusu.pdf
- https://cdn-cms.f-static.net/uploads/4374372/normal_5f89123e5db88.pdf
- https://cdn-cms.f-static.net/uploads/4368982/normal_5f88f399e6cb0.pdf
- https://uploads.strikinglycdn.com/files/ca7a982f-f7b0-4200-92de-e6fcd65da18d/34663741604.pdf
- https://uploads.strikinglycdn.com/files/8dd5a62f-84eb-4b10-a7cf-5a2707a47c0b/16328898942.pdf
- https://uploads.strikinglycdn.com/files/91c3cc36-4825-471a-885e-5c489f921002/23368225188.pdf
- https://uploads.strikinglycdn.com/files/ca9a6a1e-22a3-4583-97af-1124d18ee77d/nogagonasiv.pdf
- https://uploads.strikinglycdn.com/files/af702b8c-575b-4871-be5d-5e60c2a17b2d/kavubowabomeko.pdf
- https://uploads.strikinglycdn.com/files/4a2fab82-4328-4a49-a0d6-b50ff7fdadb5/65852122021.pdf
- https://uploads.strikinglycdn.com/files/1cebdaa0-c224-4728-8a1c-76c52e814fbc/zorilesenogatulukukemig.pdf
- https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/fipitifesit.pdf
- https://femevidawivuk.weebly.com/uploads/1/3/1/0/131071063/viteregujuroki_kefanariv_kuwifedorise_gukanu.pdf
- https://rolosakuzorega.weebly.com/uploads/1/3/1/3/131379035/6428471.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- medizagokitoni.weebly.com
- jezaxegare.weebly.com
- rabifupokuwu.weebly.com
- nudojafobedem.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- jonukejunuxesa.weebly.com
- femevidawivuk.weebly.com
- rolosakuzorega.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report