SUSPICIOUS — normal_5f8ce8076142b.pdf
SUSPICIOUS — normal_5f8ce8076142b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fa0600271383d9cc91c56145da7b858a416e733b12bfe7042322049f628552c0 - SHA-1:
66945105eca2c6d9271c4fb8c84ceae273cc1895 - MD5:
dd8b89d2beff9b074b4c123c96937444 - ssdeep:
768:FsgGzpDAp6OvSieQRPiyjGRmGAwru9U5vIGe05Oa3i3ScH0M+qHLbWboYq:7GFMp8sRwyqTfwFnLbWboYq - TLSH:
T131329DF340E7CD8CBA8AA743AEA62859514AD28C6037D76504DC772CD0FC6BDAF10961 - Submitted as: normal_5f8ce8076142b.pdf
- File type: pdf · Size: 44785 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/77240581-9cf7-4b67-95ec-78d45c87f09e/dizoka.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=framed+free+apk+android, https://cdn.shopify.com/s/files/1/0483/3669/9555/files/south_lomei_labyrinth_guide.pdf, https://cdn.shopify.com/s/files/1/0497/2675/0881/files/2004_ford_f250_diesel_owners_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=framed+free+apk+android
- https://cdn.shopify.com/s/files/1/0483/3669/9555/files/south_lomei_labyrinth_guide.pdf
- https://cdn.shopify.com/s/files/1/0497/2675/0881/files/2004_ford_f250_diesel_owners_manual.pdf
- https://cdn.shopify.com/s/files/1/0431/1616/7328/files/nojadekebifajegalafopob.pdf
- https://cdn.shopify.com/s/files/1/0431/1682/2692/files/juxibemibosig.pdf
- https://uploads.strikinglycdn.com/files/77240581-9cf7-4b67-95ec-78d45c87f09e/dizoka.pdf
- https://uploads.strikinglycdn.com/files/94c1f533-f1cb-4bf4-aa17-22b0150cc4bf/41207006980.pdf
- https://uploads.strikinglycdn.com/files/a26c10b9-d197-4b28-98d1-323e80c8e7e3/lidaj.pdf
- https://uploads.strikinglycdn.com/files/871df800-f3ce-48a8-bd3b-1a723f3055cb/mahindra_2615_hst_owners_manual.pdf
- https://uploads.strikinglycdn.com/files/6759ba10-d663-4c5b-a588-c3e480688b2e/nezukixuwovexuzikifarab.pdf
- https://finiluxexolije.weebly.com/uploads/1/3/1/8/131856594/regutoxutavi.pdf
- https://fanawilixu.weebly.com/uploads/1/3/1/4/131408209/ranituzoxusavogew.pdf
- https://riragojefo.weebly.com/uploads/1/3/1/8/131857115/87cec15aff5.pdf
- https://cdn.shopify.com/s/files/1/0501/0279/6442/files/netupobonuz.pdf
- https://cdn.shopify.com/s/files/1/0480/7108/2148/files/praying_mantis_habitat_map.pdf
- https://uploads.strikinglycdn.com/files/ac125fce-3586-4050-96c2-26c7b7d92132/dr_kendall_ritchie_knoxville_tn.pdf
- https://uploads.strikinglycdn.com/files/d49b78d3-c8ba-4c3d-a35d-ddf8c178a791/xaxasikibupe.pdf
- https://uploads.strikinglycdn.com/files/e9fc0804-7afc-428e-a2e4-49478b829455/57030252669.pdf
- https://uploads.strikinglycdn.com/files/a4ec25a6-e256-43af-ad67-75e686da31eb/24689706505.pdf
- https://uploads.strikinglycdn.com/files/8d9e1376-9a1e-424d-a1d5-f516bfcd5c8e/kiwovibuwabolukoruwuturig.pdf
- https://uploads.strikinglycdn.com/files/84f5cf66-4306-40d6-acb5-f50c44283e87/sofobi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- finiluxexolije.weebly.com
- fanawilixu.weebly.com
- riragojefo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report