SUSPICIOUS — normal_5f8bceac5217b.pdf
SUSPICIOUS — normal_5f8bceac5217b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e288534bf60af6ffa3da9a0cb650941b0b5444a92829aa5dc9d23fe9255f9df8 - SHA-1:
41593712d1f3fff502da69443c3e1b692d8b3b7b - MD5:
96220cec0c922c88c8a0ab10e1d7645c - ssdeep:
1536:gGF3efhufaCpOlSaHGlmfTCMwUelsPAhWtU4jA8RC:tF3efhufAJwUelsYEtXA1 - TLSH:
T1F839D0F350A7DD8C3AC7DB03AEE619589588C284A1328B9044CD777DC87C67CBE449A5 - Submitted as: normal_5f8bceac5217b.pdf
- File type: pdf · Size: 91226 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/348aa915-61be-4c3c-a3ad-ce2889a86ee1/61515553555.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/123?keyword=tv+guide+bbc+1+london, https://uploads.strikinglycdn.com/files/348aa915-61be-4c3c-a3ad-ce2889a86ee1/61515553555.pdf, https://uploads.strikinglycdn.com/files/5407ca7d-7e49-432f-8bb7-8c3a33d5b5c4/zegetu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/123?keyword=tv+guide+bbc+1+london
- https://uploads.strikinglycdn.com/files/348aa915-61be-4c3c-a3ad-ce2889a86ee1/61515553555.pdf
- https://uploads.strikinglycdn.com/files/5407ca7d-7e49-432f-8bb7-8c3a33d5b5c4/zegetu.pdf
- https://uploads.strikinglycdn.com/files/6283f699-f33e-4533-944e-25ea10e455c4/17984509673.pdf
- https://uploads.strikinglycdn.com/files/cfe73cfd-bd1e-4928-9473-832a576d835f/firudegidinakezepag.pdf
- https://uploads.strikinglycdn.com/files/a4769219-5e26-4599-bd04-45420c3493d0/43840324416.pdf
- https://uploads.strikinglycdn.com/files/ad27735f-a144-456d-87d6-2335bf04cf1a/sajejexifejisum.pdf
- https://uploads.strikinglycdn.com/files/faf3eb17-d168-47b8-9332-b726b6748916/zamulobelezozuxi.pdf
- https://rewemekekebaz.weebly.com/uploads/1/3/1/4/131406535/851b143458c0.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/8767144.pdf
- https://bizetuxerupa.weebly.com/uploads/1/3/0/8/130873791/xapefoputazin.pdf
- https://nipaxibovaj.weebly.com/uploads/1/3/1/3/131379211/5ed7cc.pdf
- https://cdn.shopify.com/s/files/1/0501/8786/2194/files/complex_and_compound_complex_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0428/5176/2343/files/aceites_esenciales_y_sus_usos.pdf
- https://uploads.strikinglycdn.com/files/7d602f30-b542-4a8d-8d7e-1026b8c87f26/the_law_of_retribution.pdf
- https://uploads.strikinglycdn.com/files/564e0533-ef08-4064-9755-99a7fbf9824a/79887830140.pdf
- https://uploads.strikinglycdn.com/files/319fb3d6-9094-4771-9fab-d30bb35eb9df/95741464261.pdf
- https://uploads.strikinglycdn.com/files/04816777-1f2d-49aa-937a-532c1260651a/jofarogebuses.pdf
- https://cdn.shopify.com/s/files/1/0479/5518/1724/files/savimi.pdf
- https://cdn.shopify.com/s/files/1/0500/0101/9030/files/ch_products_flight_sim_yoke_calibration.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- rewemekekebaz.weebly.com
- dimaxafazeza.weebly.com
- bizetuxerupa.weebly.com
- nipaxibovaj.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report