SUSPICIOUS — normal_5f8b5f4c5b542.pdf
SUSPICIOUS — normal_5f8b5f4c5b542.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f775b2206878f6ec4eba940a8bafd451531dbdb87033acb1e204c7f966037c04 - SHA-1:
ef028793409cbda71709fb1c6ef65a7b6478463b - MD5:
569f06e183aab94e90dfa57ca4cc9c5b - ssdeep:
768:ugGzpDCpbe/Snu8SYrbCrkClIgj3FxobwI5RWUCNeQ+rw7/t8y2wm1j7:LGFmpMJsaybwI5RWQq7/Syzm1j7 - TLSH:
T15F339EF350ABED4C798B7B137DA61469A08AD3C86136979009CC372CC47CAED3E50A65 - Submitted as: normal_5f8b5f4c5b542.pdf
- File type: pdf · Size: 47609 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/3e0bd764-b48a-45d0-aa48-2cdc5d5db186/72946027785.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=christmas+vocabulary+esl+worksheet, https://uploads.strikinglycdn.com/files/3e0bd764-b48a-45d0-aa48-2cdc5d5db186/72946027785.pdf, https://uploads.strikinglycdn.com/files/d2a08d8a-3cc7-48c9-9d9f-a44a3e56f1f7/fipomiwalekedutazijavop.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=christmas+vocabulary+esl+worksheet
- https://uploads.strikinglycdn.com/files/3e0bd764-b48a-45d0-aa48-2cdc5d5db186/72946027785.pdf
- https://uploads.strikinglycdn.com/files/d2a08d8a-3cc7-48c9-9d9f-a44a3e56f1f7/fipomiwalekedutazijavop.pdf
- https://uploads.strikinglycdn.com/files/639878b3-75e8-495a-804c-a8894ee2949c/90185996591.pdf
- https://uploads.strikinglycdn.com/files/c8938a24-33a6-4b3b-ad23-8447206c76df/70883767306.pdf
- https://uploads.strikinglycdn.com/files/5a43417f-5838-47e8-8dc4-7bd9bf5a384c/59346744247.pdf
- https://cdn-cms.f-static.net/uploads/4367308/normal_5f8ace4af02f8.pdf
- https://uploads.strikinglycdn.com/files/731c0782-41da-410f-9191-8ddb0a21ecff/ganavajiwobikutuvebosoka.pdf
- https://uploads.strikinglycdn.com/files/6250b177-6936-4e82-96c3-00162963cd44/latetulutapojibab.pdf
- https://uploads.strikinglycdn.com/files/3731abcf-2748-4509-8e8a-b70b4c6e2583/35805896419.pdf
- https://uploads.strikinglycdn.com/files/4573d49a-6302-4b66-a7d4-2e245ebb2b4e/34911151028.pdf
- https://uploads.strikinglycdn.com/files/57502951-bb50-4bd6-aa15-d36d015b3c2d/50377614002.pdf
- https://cdn-cms.f-static.net/uploads/4378848/normal_5f8a586c9b919.pdf
- https://cdn-cms.f-static.net/uploads/4367290/normal_5f87437b42891.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f89d51b8761d.pdf
- https://cdn-cms.f-static.net/uploads/4366399/normal_5f8b5e9a0fdf6.pdf
- https://uploads.strikinglycdn.com/files/ac057fb6-96d5-495e-8fc3-6023a4fcf751/10856637752.pdf
- https://uploads.strikinglycdn.com/files/1e11728a-a35f-4042-9ddf-d274eaa8f086/33296365777.pdf
- https://uploads.strikinglycdn.com/files/2df60bd3-fe92-43ae-837c-d2fc292e43fc/12375485146.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report