SUSPICIOUS — normal_5f87685a2e7cd.pdf
SUSPICIOUS — normal_5f87685a2e7cd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d76d09cdf9f40df13c2b87939b0acf90cd954958aab9cafe01fd62d8320e4e3c - SHA-1:
f68cbf3d55b6f2e3a378ef44be66c8e6b0c3142f - MD5:
b2731a90872f8658f743d4b8fd11d655 - ssdeep:
768:ugGzpDLp8k4C9y3KDT8+ML6rfEM3FI+yRj7IezE0Mw9L2QEXw/NoQ4+AzZqwoOg:LGF3ph4CU6DT8/GrfLzwkw/NqxswoOg - TLSH:
T19F33BFF390A7ED4C7A8F6B436EBB219A6509C7482132A370458C272DD4BCAFD7E50611 - Submitted as: normal_5f87685a2e7cd.pdf
- File type: pdf · Size: 49705 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/86e62072-aefb-45bf-a75c-83e213b694d5/kebevasovezarawafin.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=physics+textbook+high+school+pdf, https://site-1042284.mozfiles.com/files/1042284/5249427183.pdf, https://site-1042969.mozfiles.com/files/1042969/wikebu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=physics+textbook+high+school+pdf
- https://site-1042284.mozfiles.com/files/1042284/5249427183.pdf
- https://site-1042969.mozfiles.com/files/1042969/wikebu.pdf
- https://site-1038526.mozfiles.com/files/1038526/57140917995.pdf
- https://uploads.strikinglycdn.com/files/86e62072-aefb-45bf-a75c-83e213b694d5/kebevasovezarawafin.pdf
- https://uploads.strikinglycdn.com/files/16972430-e7b4-49e1-bc7b-8107c54a7fa0/25516650746.pdf
- https://uploads.strikinglycdn.com/files/e5e48312-f384-49df-8dd7-5712db8c79bc/musan.pdf
- https://uploads.strikinglycdn.com/files/383f5e60-d518-4a55-8c98-c946e6028f0e/xamed.pdf
- https://uploads.strikinglycdn.com/files/ebce8290-cee3-49d7-b104-ac6bf8553aa3/wipejox.pdf
- https://uploads.strikinglycdn.com/files/34ca301b-42fa-4474-a746-de6cc88ec554/mojiwuz.pdf
- https://uploads.strikinglycdn.com/files/067a1912-dd31-48a7-b6e7-2fe8439821cc/walemavilebajigasofil.pdf
- https://uploads.strikinglycdn.com/files/d2caf854-5d57-4f7d-80bd-8bc00c7bcc78/33910473557.pdf
- https://uploads.strikinglycdn.com/files/e808f969-0c9e-4459-88d2-7241025ad2f6/gutadogikaji.pdf
- https://uploads.strikinglycdn.com/files/622a85f1-ac1d-4579-96d2-9920e47cff91/sobejizivilipexogeradiwo.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f872c1403372.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f8755a34b52a.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f8767497d61e.pdf
- https://cdn-cms.f-static.net/uploads/4367650/normal_5f876717a523f.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f873d97d2c08.pdf
- https://cdn.shopify.com/s/files/1/0435/6138/6147/files/51899399715.pdf
- https://cdn.shopify.com/s/files/1/0492/4565/1100/files/futevem.pdf
- https://cdn.shopify.com/s/files/1/0497/1462/6717/files/54906109198.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- site-1042284.mozfiles.com
- site-1042969.mozfiles.com
- site-1038526.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report