SUSPICIOUS — normal_5f882984a5e92.pdf
SUSPICIOUS — normal_5f882984a5e92.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ea0b36a88fed31a4018c558fe906ae043180f59d7c265f1e097cf498a304045f - SHA-1:
e65697cdc1326b1060122ac0e874a32b7cf6f4c0 - MD5:
689eaa27b255c81d068f3b5dbc3ade43 - ssdeep:
768:9gGzpDYpCjqXCGZ4XR366d4bkpecqZVkG47oxGyLUgKkPcs/UYEgpbjN:+GFspC3npBqVEyLUgHUYNbjN - TLSH:
T135339EF31093EC9C3A8EAF435EB7018D758AC789653257A098CC266CD5B86EC7F10A51 - Submitted as: normal_5f882984a5e92.pdf
- File type: pdf · Size: 48682 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/47080e5e-3219-42bd-9a23-8cb989fb4085/93540528305.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=olympus+pen+mini+e-pm1+manual, https://site-1039573.mozfiles.com/files/1039573/16345623098.pdf, https://site-1048168.mozfiles.com/files/1048168/gogamapetapupipes.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=olympus+pen+mini+e-pm1+manual
- https://site-1039573.mozfiles.com/files/1039573/16345623098.pdf
- https://site-1048168.mozfiles.com/files/1048168/gogamapetapupipes.pdf
- https://site-1040503.mozfiles.com/files/1040503/39541314450.pdf
- https://uploads.strikinglycdn.com/files/47080e5e-3219-42bd-9a23-8cb989fb4085/93540528305.pdf
- https://cdn-cms.f-static.net/uploads/4367277/normal_5f87facae5f0c.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f86fc8e06e99.pdf
- https://cdn.shopify.com/s/files/1/0435/5555/3432/files/iron_kingdoms_fillable_character_sheet.pdf
- https://cdn.shopify.com/s/files/1/0478/3502/1471/files/kijamelajujobibejutowu.pdf
- https://cdn.shopify.com/s/files/1/0478/7703/0054/files/wegabuzopun.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/kinufijozulof.pdf
- https://wekubuzebebam.weebly.com/uploads/1/3/0/7/130739705/a785a026bb.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/botisipizuz_supixikikijowa_kabexodonu.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/gegakunagakamet-wipumidujo.pdf
- https://uploads.strikinglycdn.com/files/863bf323-2351-491f-9ee5-2a3d72c4b44b/88790404960.pdf
- https://uploads.strikinglycdn.com/files/4c4f1f29-0517-4123-b90a-c7cc1fc05827/sosokirexafalasopavefof.pdf
- https://uploads.strikinglycdn.com/files/d3765281-836f-4bcb-8255-2c0df94c27bf/dilavagexudelomuworonenu.pdf
- https://uploads.strikinglycdn.com/files/70a65c9a-6f6f-4bee-ac23-4e9c04e6f44c/mofikakidin.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1039573.mozfiles.com
- site-1048168.mozfiles.com
- site-1040503.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- vuxozajuje.weebly.com
- wekubuzebebam.weebly.com
- zesopupejilit.weebly.com
- walijogopabo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report