SUSPICIOUS — normal_5f9352515d0ff.pdf
SUSPICIOUS — normal_5f9352515d0ff.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e3d1f3fdd2d00934609186761964ac2ca3e3c3bec2008467c827501be26a8fd5 - SHA-1:
98dfb3bf5d0697c9a516fb7d815a5c8a6626b67b - MD5:
cfed0e041542a65c8dd308fb66c459b2 - ssdeep:
768:/gGzpDsjWbrDbtKVSZW7YBf9AsHnWFDdVqP+4ZHBPsGrkUr6Mea:IGFgmw5kBFrHnWFDPU+4BdprkUr6Mea - TLSH:
T135317DF350A7FD8C7E8B5B83ADAB12992146D78CB122D2A01598763CC53C6EDBF00561 - Submitted as: normal_5f9352515d0ff.pdf
- File type: pdf · Size: 40120 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/d3492302-13e3-4359-b21e-81f988757381/new_years_eve_18_and_over.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=crimpadora+manual+mangueras+hidraulicas, https://uploads.strikinglycdn.com/files/d3492302-13e3-4359-b21e-81f988757381/new_years_eve_18_and_over.pdf, https://uploads.strikinglycdn.com/files/581c50c1-bef6-479a-944e-f1ce2ab502c4/72286732448.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=crimpadora+manual+mangueras+hidraulicas
- https://uploads.strikinglycdn.com/files/d3492302-13e3-4359-b21e-81f988757381/new_years_eve_18_and_over.pdf
- https://uploads.strikinglycdn.com/files/581c50c1-bef6-479a-944e-f1ce2ab502c4/72286732448.pdf
- https://uploads.strikinglycdn.com/files/c0096e64-23df-4499-977a-7348ec9ae922/diseo_narrativo_toolkit.pdf
- https://cdn.shopify.com/s/files/1/0492/7756/7132/files/alarm_clock_in_android_example.pdf
- https://cdn.shopify.com/s/files/1/0484/7606/1850/files/osrs_pure_nmz_guide_2018.pdf
- https://cdn.shopify.com/s/files/1/0482/7653/7499/files/nvivo_free_trial.pdf
- https://cdn.shopify.com/s/files/1/0486/2109/3029/files/bodonetivebakurulirado.pdf
- https://zidabowejixu.weebly.com/uploads/1/3/1/1/131163559/tabogozotutapo-mojijasenubizob-zubalubadufuxe-guwakipovom.pdf
- https://zizuralozirufu.weebly.com/uploads/1/3/1/4/131483034/jikorisokoxuwuvog.pdf
- https://jowodetuleguzu.weebly.com/uploads/1/3/1/8/131856173/73c5087beb4.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/xixaparunixigoz_fokasisatetiful_lujeloralugomuf_jipowovogoz.pdf
- https://lozulijulejibog.weebly.com/uploads/1/3/1/8/131857057/nafosov-famedude-jilowep-zagikakigatod.pdf
- https://cdn.shopify.com/s/files/1/0493/7534/6847/files/emotional_appeal_in_advertising.pdf
- https://cdn.shopify.com/s/files/1/0497/9746/4226/files/mini_militia_army_war_mod_apk_download.pdf
- https://s3.amazonaws.com/fedufiporara/75608801480.pdf
- https://s3.amazonaws.com/tetazino/ecological_succession_activity.pdf
- https://s3.amazonaws.com/litunux/adda247_math_book.pdf
- https://s3.amazonaws.com/zirojopemup/ielts_essay_writing_topics_with_answers.pdf
- https://s3.amazonaws.com/pazifetanegapu/76690230204.pdf
- https://s3.amazonaws.com/janodojivi/76367718154.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- zidabowejixu.weebly.com
- zizuralozirufu.weebly.com
- jowodetuleguzu.weebly.com
- vilukenuxe.weebly.com
- lozulijulejibog.weebly.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report