SUSPICIOUS — normal_5f87856a81a64.pdf
SUSPICIOUS — normal_5f87856a81a64.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ba4c80e9be536c86db848e6cf574673d94298924769768fa6e9e9fff2def3766 - SHA-1:
446b7d9f1600e96cc9b54b405c626c042a1caf2a - MD5:
7c26232c958753184dd2fcac14ce29a8 - ssdeep:
768:ImgGzpDfpGa/YeCA/XtLBR7ZMLull+sCJln9Nn4BHVvgGE7bmHCLx:OGF7pVXtlRCe+sCJln9NnbvbmHCLx - TLSH:
T1E9328DF348A7EC4CBB8A9B03ADBA2559109AC3896137D760444C776DD4BC67EBF10821 - Submitted as: normal_5f87856a81a64.pdf
- File type: pdf · Size: 45453 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/c1c446bd-e720-4c14-9cab-b5f9046b541c/kaxuwexuwa.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=terraria+android+full+apk+obb, https://liwevapazu.weebly.com/uploads/1/3/1/0/131071299/1315167.pdf, https://vevejeda.weebly.com/uploads/1/3/0/7/130776099/86bd3b89c294ae.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=terraria+android+full+apk+obb
- https://liwevapazu.weebly.com/uploads/1/3/1/0/131071299/1315167.pdf
- https://vevejeda.weebly.com/uploads/1/3/0/7/130776099/86bd3b89c294ae.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/zebapesuluboxaj.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/fubaxin.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/4815124.pdf
- https://uploads.strikinglycdn.com/files/c1c446bd-e720-4c14-9cab-b5f9046b541c/kaxuwexuwa.pdf
- https://uploads.strikinglycdn.com/files/7003bbb8-3dd8-44a0-ba00-230c92688a5d/45382126666.pdf
- https://uploads.strikinglycdn.com/files/64c6d1fe-198a-47a3-8361-70f2c1f5e184/wexupisamuxida.pdf
- https://uploads.strikinglycdn.com/files/c5a233e6-8595-48ca-8c01-16e3cc2d558e/21770698526.pdf
- https://site-1048531.mozfiles.com/files/1048531/dokagona.pdf
- https://site-1040036.mozfiles.com/files/1040036/xivirubitivobazufajadow.pdf
- https://site-1037091.mozfiles.com/files/1037091/pezixawuramamuditiron.pdf
- https://site-1038738.mozfiles.com/files/1038738/25531728809.pdf
- https://site-1036761.mozfiles.com/files/1036761/39042844760.pdf
- https://cdn.shopify.com/s/files/1/0486/2564/7784/files/meid_writer_apk.pdf
- https://cdn.shopify.com/s/files/1/0499/9810/2678/files/waukesha_county_property_tax.pdf
- https://cdn.shopify.com/s/files/1/0485/0689/6539/files/xafupepolixe.pdf
- https://cdn.shopify.com/s/files/1/0484/3588/8296/files/what_does_archived_classes_mean.pdf
- https://uploads.strikinglycdn.com/files/4bce3d0c-81c8-489f-99b3-b940b56e9c0e/76361074035.pdf
- https://uploads.strikinglycdn.com/files/fb9d5ad8-924b-48c0-b315-778ff98abf6d/23572916015.pdf
- https://uploads.strikinglycdn.com/files/4e2731bb-947e-4898-b8c0-6e677f4ab4e3/pirodos.pdf
- https://uploads.strikinglycdn.com/files/a87cb7f4-9540-4b6a-9d5c-619652ae2c84/jebimuzevipefi.pdf
- https://uploads.strikinglycdn.com/files/4f7f4201-45f9-44a8-9c04-218fee7713af/nonaliwurudezularefel.pdf
- https://site-1039342.mozfiles.com/files/1039342/ratagad.pdf
Embedded domains
- ggtraff.ru
- liwevapazu.weebly.com
- vevejeda.weebly.com
- xojerajap.weebly.com
- walijogopabo.weebly.com
- tavumake.weebly.com
- uploads.strikinglycdn.com
- site-1048531.mozfiles.com
- site-1040036.mozfiles.com
- site-1037091.mozfiles.com
- site-1038738.mozfiles.com
- site-1036761.mozfiles.com
- cdn.shopify.com
- site-1039342.mozfiles.com
- site-1042429.mozfiles.com
- site-1036936.mozfiles.com
- site-1040359.mozfiles.com
- site-1045389.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report