SUSPICIOUS — normal_5f879c4dc9399.pdf
SUSPICIOUS — normal_5f879c4dc9399.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
129de42a2225f755b627ced8653631a5a20d8410d849ac49e945caf6d19b082e - SHA-1:
b14341b7da354dd2f7da8b53c6ee64f71c445001 - MD5:
4c82eacfb7288c74d2374bdb4da741e9 - ssdeep:
1536:PGFrp1l4L9KKcRRd4vG1iXzelmeuWwKp/7ZYBZ:+Frpb4L9KKcuvG1ijelmemO7Q - TLSH:
T1E8349EF324B7DC4D7A8BAF03ADEA2155614ADB886136E76055887B2CC1BC7BC3E01950 - Submitted as: normal_5f879c4dc9399.pdf
- File type: pdf · Size: 52489 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/70b18188-d754-44d3-b86e-10f0a141fc08/rurabapulakusuwodebuw.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=kodiak+cakes+mix+instructions, https://uploads.strikinglycdn.com/files/70b18188-d754-44d3-b86e-10f0a141fc08/rurabapulakusuwodebuw.pdf, https://uploads.strikinglycdn.com/files/4eb4e566-6922-47bc-a7fe-0972aa681c69/kofodumaja.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=kodiak+cakes+mix+instructions
- https://uploads.strikinglycdn.com/files/70b18188-d754-44d3-b86e-10f0a141fc08/rurabapulakusuwodebuw.pdf
- https://uploads.strikinglycdn.com/files/4eb4e566-6922-47bc-a7fe-0972aa681c69/kofodumaja.pdf
- https://uploads.strikinglycdn.com/files/ec687549-a69e-4f86-b9a5-3f5a5efdbe0d/51522131191.pdf
- https://cdn.shopify.com/s/files/1/0434/0426/3585/files/zuradidonudiz.pdf
- https://cdn.shopify.com/s/files/1/0430/7619/0361/files/decoupage_tutorial_decorating_candles_with_napkins.pdf
- https://cdn.shopify.com/s/files/1/0499/2191/7086/files/18755174243.pdf
- https://cdn.shopify.com/s/files/1/0484/3991/8742/files/95873198140.pdf
- https://cdn.shopify.com/s/files/1/0431/5784/8224/files/31501752361.pdf
- https://uploads.strikinglycdn.com/files/3b1ea4d3-555e-4306-a833-e81bed439160/40414959495.pdf
- https://uploads.strikinglycdn.com/files/783fbb3a-3e7f-456b-aeb7-72d5306b5bbc/xorik.pdf
- https://uploads.strikinglycdn.com/files/358fe904-ebea-4e67-8b44-cad75de3c34c/34161987952.pdf
- https://cdn.shopify.com/s/files/1/0487/0861/6342/files/the_watch_repairers_manual.pdf
- https://cdn.shopify.com/s/files/1/0465/9413/0085/files/amd_catalyst_install_manager_uninstall.pdf
- https://uploads.strikinglycdn.com/files/305e08cf-242a-42b8-b04f-01bcb4d62a38/movazonidew.pdf
- https://uploads.strikinglycdn.com/files/7a171af6-ab90-4ebf-a687-8a7175bdac75/lofetobajipebutu.pdf
- https://uploads.strikinglycdn.com/files/dc349ee5-8903-4eb4-904f-fd080ab478d4/refojabarikagekazusanon.pdf
- https://uploads.strikinglycdn.com/files/47c2a158-d63d-4a67-a9fd-3ae3d76654da/mugojonamujibexewudur.pdf
- https://uploads.strikinglycdn.com/files/e935c6a2-3344-4f00-905a-997a412e8c0c/64845001436.pdf
- https://uploads.strikinglycdn.com/files/7c7e2581-2a47-4277-9839-e4b9f8fd8b95/kidojotebalolajofigim.pdf
- https://uploads.strikinglycdn.com/files/97343b9e-bdf8-4172-b032-ec5e3b0fd0bd/zuwawadafisepo.pdf
- https://uploads.strikinglycdn.com/files/68813644-b6a1-4c67-8a19-7c2c3955a116/widanozunoseziw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report