SUSPICIOUS — normal_5f8717092c5c6.pdf
SUSPICIOUS — normal_5f8717092c5c6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bd4b40e864aa61276135f913fa927d4d2c7089c4dc30d78c2058744be9cafbf5 - SHA-1:
a7080d2a602ecea07d7d4be322fe0d96712918e6 - MD5:
4d6f8ba669c0e7a6c2769eb6082996b7 - ssdeep:
768:jgGzpDFp8hmEEdkCTOZOLS238soiDZBQcSMoxukSYlRGf:cGFhp8GTZLnMmscSbxukSYl4f - TLSH:
T12E328FF354A7EC8C7A8BAF439D97056D614BC6846177976019E8372CD0BCAFC6D10920 - Submitted as: normal_5f8717092c5c6.pdf
- File type: pdf · Size: 47493 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/b1c2ea2f-43eb-4941-9f79-a0ad0464d323/48896392613.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=download+vsco+x+full+pack+apk+2020, https://uploads.strikinglycdn.com/files/4f2c6ccd-ae0f-497d-b4fd-a93b3008b43e/42808175309.pdf, https://uploads.strikinglycdn.com/files/ff19d1de-f727-4fc5-ad05-ec74b6610bd7/ridojefekavukapaluvu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=download+vsco+x+full+pack+apk+2020
- https://uploads.strikinglycdn.com/files/4f2c6ccd-ae0f-497d-b4fd-a93b3008b43e/42808175309.pdf
- https://uploads.strikinglycdn.com/files/ff19d1de-f727-4fc5-ad05-ec74b6610bd7/ridojefekavukapaluvu.pdf
- https://uploads.strikinglycdn.com/files/76534128-7322-45a0-bf78-8394ae48ca08/ferolaz.pdf
- https://uploads.strikinglycdn.com/files/b1c2ea2f-43eb-4941-9f79-a0ad0464d323/48896392613.pdf
- https://uploads.strikinglycdn.com/files/cb1393fb-ff1e-4e0a-a386-eb75e8606e8f/nezoxemubepevixe.pdf
- https://uploads.strikinglycdn.com/files/a0180e00-53f7-41b2-b107-8c29c1547898/99619293715.pdf
- https://uploads.strikinglycdn.com/files/424c2218-6d20-4f54-a651-11fed2be4029/vovivaxedefeg.pdf
- https://uploads.strikinglycdn.com/files/e640b5fd-8b2b-4572-89bd-182f32b9ea49/86230827651.pdf
- https://cdn.shopify.com/s/files/1/0498/6624/4251/files/taco_bell_chicken_quesadilla_calories.pdf
- https://cdn.shopify.com/s/files/1/0432/6912/8354/files/31863484299.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/3722212.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/3532345.pdf
- https://narogigadi.weebly.com/uploads/1/3/0/8/130874066/c2099e721b.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bewoti.pdf
- https://uploads.strikinglycdn.com/files/fca71fa4-4f12-4627-a496-448e83b405eb/puximatuwiximodapumonoz.pdf
- https://uploads.strikinglycdn.com/files/79cb97e4-8c0c-4c7d-9281-79919b627834/xedivebisusozijitizededa.pdf
- https://uploads.strikinglycdn.com/files/82b79c14-58db-4202-a022-dfcb2fb76347/juxokexebaxezudulab.pdf
- https://site-1040339.mozfiles.com/files/1040339/16155281924.pdf
- https://site-1037069.mozfiles.com/files/1037069/12819723050.pdf
- https://site-1036838.mozfiles.com/files/1036838/53565169221.pdf
- https://site-1038658.mozfiles.com/files/1038658/34871740948.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- jawasolasazilem.weebly.com
- zoxuzuxebexot.weebly.com
- narogigadi.weebly.com
- vuxozajuje.weebly.com
- site-1040339.mozfiles.com
- site-1037069.mozfiles.com
- site-1036838.mozfiles.com
- site-1038658.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report