SUSPICIOUS — normal_5f8744c122690.pdf
SUSPICIOUS — normal_5f8744c122690.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b0ab0f08d1e2395ecd22e985884a37fa00f6cfcf1a335f709a4941ba860f11fd - SHA-1:
43c73465fd8be8cb507832d9431af5971dd2c5fd - MD5:
9baefe3452efdcfa564f00ad23fbbad5 - ssdeep:
1536:gGFpe0zyvTVjSGgDUVztVGjMhGamjgSaOJb:tFpeQyoZDU3V8pamjRh - TLSH:
T1A5349DF75193DC8C7A8A6F039DF711D9614AC38D3232D7A01888772CD17C6ACAE11AA5 - Submitted as: normal_5f8744c122690.pdf
- File type: pdf · Size: 57522 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/1238de55-d1e1-4b3a-ab00-235f992468bb/35745453176.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=political+history+of+japan+pdf, https://site-1043976.mozfiles.com/files/1043976/gomemamurutupujevoz.pdf, https://site-1039897.mozfiles.com/files/1039897/97878128094.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=political+history+of+japan+pdf
- https://site-1043976.mozfiles.com/files/1043976/gomemamurutupujevoz.pdf
- https://site-1039897.mozfiles.com/files/1039897/97878128094.pdf
- https://site-1043195.mozfiles.com/files/1043195/bizidetetubudo.pdf
- https://vibebivenef.weebly.com/uploads/1/3/1/4/131412032/7ab649c307f4d.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/dekefomivupe-kovak-talajonipa-fedebiraroz.pdf
- https://site-1040242.mozfiles.com/files/1040242/wujawazomodilo.pdf
- https://site-1037267.mozfiles.com/files/1037267/94968608383.pdf
- https://uploads.strikinglycdn.com/files/1238de55-d1e1-4b3a-ab00-235f992468bb/35745453176.pdf
- https://uploads.strikinglycdn.com/files/21a69eb0-2cdb-4604-b32b-6974d0509126/9272392438.pdf
- https://uploads.strikinglycdn.com/files/33797ab5-2e76-41b3-8c54-650370039108/4543342493.pdf
- https://uploads.strikinglycdn.com/files/399ef1eb-b698-407e-99fb-530bb18ad75d/jikagitoji.pdf
- https://uploads.strikinglycdn.com/files/8d4a91e2-45ac-47dc-972e-60ef9966b15b/gufukogakexidejid.pdf
- https://uploads.strikinglycdn.com/files/7f84e686-bebb-46ca-8ea4-dc6eaf7350d8/17217872998.pdf
- https://uploads.strikinglycdn.com/files/23fb0b86-04b2-4a39-b754-1058108afba7/55992032773.pdf
- https://uploads.strikinglycdn.com/files/f929c1e1-b5e0-421d-aa0e-8e47b2c34ac2/xodexumupurazura.pdf
- https://uploads.strikinglycdn.com/files/0af163b6-2386-49eb-88db-65dd7bf7512e/minujekanitike.pdf
- https://uploads.strikinglycdn.com/files/03698443-4115-4240-9189-e947751d62a3/34629713815.pdf
- https://uploads.strikinglycdn.com/files/c67f276a-f1b4-473a-a2fe-2ca20ade45dd/55849549566.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1043976.mozfiles.com
- site-1039897.mozfiles.com
- site-1043195.mozfiles.com
- vibebivenef.weebly.com
- zoxuzuxebexot.weebly.com
- site-1040242.mozfiles.com
- site-1037267.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report