SUSPICIOUS — normal_5f8a2273a427b.pdf
SUSPICIOUS — normal_5f8a2273a427b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b59a01bc10c2b03105dbef791eee41b96e125d8e661f55db1714142ade8ec089 - SHA-1:
36513683fb79c88f4e816c311723d42c38789bf4 - MD5:
ac28de429a7491139e148547ffe8a565 - ssdeep:
768:EgGzpDQpjc44irALEOCwbiHcnPFjhSjlcoc4DgyaoH80Nj0JGP1vBxjIm4g3PAR1:xGFMp44Ci8nP1hY1LBxjImr3YQBW5 - TLSH:
T1C2337CF790EBDD4C7A869F57AEAA15285049CB8960239B7048CC772CC07C2BD7E50950 - Submitted as: normal_5f8a2273a427b.pdf
- File type: pdf · Size: 49525 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/92079362-5aa0-478b-b036-bf8aae6fdb63/poxolonesazuwanipodawew.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=illy+x1+anniversary+espresso+machine+manual, https://cdn.shopify.com/s/files/1/0486/1345/8080/files/eden_prairie_schools_news.pdf, https://cdn.shopify.com/s/files/1/0500/5718/3400/files/kindly_reminder_lyrics.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/123?keyword=illy+x1+anniversary+espresso+machine+manual
- https://cdn.shopify.com/s/files/1/0486/1345/8080/files/eden_prairie_schools_news.pdf
- https://cdn.shopify.com/s/files/1/0500/5718/3400/files/kindly_reminder_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0429/7831/2355/files/personal_and_professional_goals_for_teachers.pdf
- https://cdn.shopify.com/s/files/1/0483/9800/8472/files/subafodotasuk.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f8749d59353f.pdf
- https://cdn-cms.f-static.net/uploads/4365661/normal_5f87469f8f26f.pdf
- https://uploads.strikinglycdn.com/files/4d7850be-294f-456c-ae76-4ff623f3c131/77527613402.pdf
- https://uploads.strikinglycdn.com/files/d503b724-7320-4992-8eec-0e4b776bbb77/4581802426.pdf
- https://uploads.strikinglycdn.com/files/90af91e0-d305-4563-bd86-4e4236232381/93431435879.pdf
- https://uploads.strikinglycdn.com/files/92079362-5aa0-478b-b036-bf8aae6fdb63/poxolonesazuwanipodawew.pdf
- https://uploads.strikinglycdn.com/files/c17cad1c-3159-482a-8d7d-15405e7eeca7/xilenexitimufuma.pdf
- https://cdn-cms.f-static.net/uploads/4369164/normal_5f8a1ab89f788.pdf
- https://cdn-cms.f-static.net/uploads/4369909/normal_5f895b2214450.pdf
- https://cdn-cms.f-static.net/uploads/4374838/normal_5f89548778621.pdf
- https://cdn-cms.f-static.net/uploads/4371244/normal_5f88ca22c06bf.pdf
- https://cdn-cms.f-static.net/uploads/4369190/normal_5f89d10ebb887.pdf
- https://cdn-cms.f-static.net/uploads/4367914/normal_5f891cb0724b6.pdf
- https://cdn-cms.f-static.net/uploads/4365660/normal_5f877e84c86d7.pdf
- https://cdn-cms.f-static.net/uploads/4366965/normal_5f873bdb632e6.pdf
- https://uploads.strikinglycdn.com/files/350ddeb4-2ac2-4642-84dd-5515dc59b6f7/siginimefegovusutozagamid.pdf
- https://uploads.strikinglycdn.com/files/f40b9b06-dc6a-4694-bb13-8167a054eb34/diwaxufipotejisilugumida.pdf
- https://uploads.strikinglycdn.com/files/7298fb77-ef81-4922-9dae-0e6c16f608ac/31909407816.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report