SUSPICIOUS — normal_5f8730752c5f6.pdf
SUSPICIOUS — normal_5f8730752c5f6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e15be3f6c9b1a21d844a05d95c554d46bd501ab51dc6a19cb7df21cfda1d4075 - SHA-1:
e5c5c548326477d93385acc46d4cb4366fffd742 - MD5:
3d902798d676aca2305a63611d1b8263 - ssdeep:
768:GgGzpD/p0yrJ7U/UeTY3mIOT8Y+9PXAMWyS2FH2Df6r9oSt35u41byBNkxt5ZQ2:TGFLp0yJmrsJXAyhF0f6V35d5yBwt5ZJ - TLSH:
T11F327DF314A3EC4C7A8E6F039DAB105DA14AD38C6036DBA45589272CD5BC6FD6F10A41 - Submitted as: normal_5f8730752c5f6.pdf
- File type: pdf · Size: 45824 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/be265694-46a2-45f8-8d09-084639caae7f/vutitagawonularenosamo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=construction+materials+concrete+pdf, https://cdn.shopify.com/s/files/1/0493/3894/1599/files/speech_therapy_goal_bank_for_adults.pdf, https://cdn.shopify.com/s/files/1/0430/3699/9842/files/52210970011.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=construction+materials+concrete+pdf
- https://cdn.shopify.com/s/files/1/0493/3894/1599/files/speech_therapy_goal_bank_for_adults.pdf
- https://cdn.shopify.com/s/files/1/0430/3699/9842/files/52210970011.pdf
- https://cdn.shopify.com/s/files/1/0462/6946/4727/files/first_aid_2018_errata_reddit.pdf
- https://cdn.shopify.com/s/files/1/0480/9441/2963/files/8132328209.pdf
- https://cdn.shopify.com/s/files/1/0499/1192/2856/files/computer_forensics_study_guide.pdf
- https://uploads.strikinglycdn.com/files/be265694-46a2-45f8-8d09-084639caae7f/vutitagawonularenosamo.pdf
- https://uploads.strikinglycdn.com/files/8516d960-4787-49ff-8d9f-4295af98f7f8/ninonuvimirekipofititowom.pdf
- https://uploads.strikinglycdn.com/files/5e4798fb-c4e0-44ea-a17e-b8a0cd4be439/bazudawosis.pdf
- https://cdn.shopify.com/s/files/1/0440/7531/9448/files/jupel.pdf
- https://cdn.shopify.com/s/files/1/0488/3185/6805/files/hanger_unblocked_games.pdf
- https://uploads.strikinglycdn.com/files/e9d0eec5-17a4-418b-94f1-d2ad94cd1398/78614780129.pdf
- https://uploads.strikinglycdn.com/files/a75a901a-7a27-48df-b5f9-a128cf09a6b4/vodobofubeludavitesati.pdf
- https://uploads.strikinglycdn.com/files/905e634b-7022-4133-bc0e-e8db06096d49/gufoxawopisoronilutal.pdf
- https://site-1038788.mozfiles.com/files/1038788/82922149189.pdf
- https://site-1040376.mozfiles.com/files/1040376/77732850515.pdf
- https://site-1048536.mozfiles.com/files/1048536/rekapiradekusolobexe.pdf
- https://uploads.strikinglycdn.com/files/87a6054b-de9c-4ec4-903b-74c6b3b4b332/90205924095.pdf
- https://uploads.strikinglycdn.com/files/095c527d-1321-4659-88e7-f5e0ab424d3b/fegojukosipilozigojo.pdf
- https://uploads.strikinglycdn.com/files/bae7a5f5-1fa3-411a-b943-9f5bd2557796/jekodidinekumibefakezuw.pdf
- https://uploads.strikinglycdn.com/files/de5727b1-9bb0-4433-9c6d-2f279f18ce66/vujuxutodufikon.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1038788.mozfiles.com
- site-1040376.mozfiles.com
- site-1048536.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report