SUSPICIOUS — normal_5f872121ae7f7.pdf
SUSPICIOUS — normal_5f872121ae7f7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bd4236bbb9cf06303055c1a9df7a2b4565bc4c2343b5ac47037df5e47f12c8f9 - SHA-1:
ec4945585db6be4b70e6b2760db24491ff17d9dc - MD5:
e5e15751b1ca88ef05f3594500bce899 - ssdeep:
1536:HGF4pX9xM7uLOKAaFIx5Jvh13idQj7eKCfKHfxP:mF4pX9GYYjvT3sfKH1 - TLSH:
T16434AEF351A7ED5C76CB9B136EEA245D9149DA48A132E764858D372CC0BC37E2F90A00 - Submitted as: normal_5f872121ae7f7.pdf
- File type: pdf · Size: 56188 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4366063/normal_5f87053219405.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=shortwave+radio+stations+pdf, https://uploads.strikinglycdn.com/files/9d4fd897-36a0-42a6-9125-6563848e6e10/70144393750.pdf, https://uploads.strikinglycdn.com/files/127c3fa2-290d-45eb-8dec-501dc1148260/57978004996.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=shortwave+radio+stations+pdf
- https://uploads.strikinglycdn.com/files/9d4fd897-36a0-42a6-9125-6563848e6e10/70144393750.pdf
- https://uploads.strikinglycdn.com/files/127c3fa2-290d-45eb-8dec-501dc1148260/57978004996.pdf
- https://uploads.strikinglycdn.com/files/2daae189-d983-49d4-a9c1-6436509a4468/rusoledumezesojolebowakil.pdf
- https://uploads.strikinglycdn.com/files/5036c6cb-8629-42b5-a856-f5558a68c0c7/gudefaj.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f8721129bb40.pdf
- https://cdn-cms.f-static.net/uploads/4366388/normal_5f87151c6bb85.pdf
- https://fekudumubaf.weebly.com/uploads/1/3/2/6/132681201/kogog.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/1158663.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/kekikefuwu.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/4316678.pdf
- https://cdn.shopify.com/s/files/1/0484/9939/2674/files/2591639206.pdf
- https://cdn.shopify.com/s/files/1/0500/7153/5774/files/parent_stress_index.pdf
- https://cdn.shopify.com/s/files/1/0481/3432/4387/files/bebovaril.pdf
- https://cdn.shopify.com/s/files/1/0495/9846/4152/files/68937130577.pdf
- https://cdn.shopify.com/s/files/1/0483/1897/2059/files/zesokokadozalago.pdf
- https://cdn-cms.f-static.net/uploads/4366028/normal_5f86f9faefe36.pdf
- https://cdn-cms.f-static.net/uploads/4365659/normal_5f86fc0258a7d.pdf
- https://cdn-cms.f-static.net/uploads/4366063/normal_5f87053219405.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f87095c99ec8.pdf
- https://cdn-cms.f-static.net/uploads/4366351/normal_5f870fbd61b64.pdf
- https://cdn-cms.f-static.net/uploads/4366017/normal_5f8703546f328.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- fekudumubaf.weebly.com
- dutitujazekap.weebly.com
- vuxozajuje.weebly.com
- loguxofe.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report