SUSPICIOUS — normal_5f8cad3bd6289.pdf
SUSPICIOUS — normal_5f8cad3bd6289.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bf737dfa95acf2122e5723319d86049ccea4cb0bf5801b0361010eb811d434f0 - SHA-1:
49da388e500998e699f1621779ef7378959663b9 - MD5:
ef76846d7b568d5d23b960e2463e946e - ssdeep:
1536:tGFjpTGOBRpMEg62Z6/LINUPNrvH1uQfW9S/ddx:wFjpTHaEJ2szIYNBJwgd - TLSH:
T15835B0F350EBED4C7B8A9B43AEAA15256156830C6137C7A04489772CC4FC6FDBE11A60 - Submitted as: normal_5f8cad3bd6289.pdf
- File type: pdf · Size: 61975 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/00514ce1-b9c9-42c4-be9c-68259bc7ec6c/87942154705.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=wifi+calling+not+working+android, https://cdn-cms.f-static.net/uploads/4369309/normal_5f88df67c87a2.pdf, https://cdn-cms.f-static.net/uploads/4366376/normal_5f8726cb2bf58.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=wifi+calling+not+working+android
- https://cdn-cms.f-static.net/uploads/4369309/normal_5f88df67c87a2.pdf
- https://cdn-cms.f-static.net/uploads/4366376/normal_5f8726cb2bf58.pdf
- https://cdn-cms.f-static.net/uploads/4373264/normal_5f890a8e98f28.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f88b7a63ac4c.pdf
- https://wefolukozik.weebly.com/uploads/1/3/1/4/131406413/7834490.pdf
- https://biwugina.weebly.com/uploads/1/3/1/1/131163984/4340692.pdf
- https://uploads.strikinglycdn.com/files/00514ce1-b9c9-42c4-be9c-68259bc7ec6c/87942154705.pdf
- https://uploads.strikinglycdn.com/files/7b920591-8295-4d44-ba55-2c381b3d5fba/20947470904.pdf
- https://uploads.strikinglycdn.com/files/dc7b7451-db69-4835-8e40-47f4d8b36d53/bisabejukajuwaworuloniz.pdf
- https://uploads.strikinglycdn.com/files/e5b4f551-57aa-4a75-9386-7cb6fe39019d/89931712373.pdf
- https://uploads.strikinglycdn.com/files/fffc6d2e-6e00-4065-a2e7-5a0243a6411d/piresedudagoxozu.pdf
- https://cdn-cms.f-static.net/uploads/4373259/normal_5f8940bb784c2.pdf
- https://cdn-cms.f-static.net/uploads/4371523/normal_5f8b571dc547a.pdf
- https://uploads.strikinglycdn.com/files/e172f007-a8b2-402d-bead-ca9e11072d5a/vugefekazegorasiguvapug.pdf
- https://uploads.strikinglycdn.com/files/512513bf-4855-4192-8048-ab4aebb785ec/23835763260.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/vovofofaverun_sawivurovoj_nifawubazox.pdf
- https://jezaxegare.weebly.com/uploads/1/3/1/3/131380636/fuzozilulapi_fakaf.pdf
- https://roninuvanajeg.weebly.com/uploads/1/3/1/3/131379749/7745478.pdf
- https://zelapagetuwuj.weebly.com/uploads/1/3/1/4/131406140/c85f0cbef.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- wefolukozik.weebly.com
- biwugina.weebly.com
- uploads.strikinglycdn.com
- genigudepa.weebly.com
- jezaxegare.weebly.com
- roninuvanajeg.weebly.com
- zelapagetuwuj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report