SUSPICIOUS — normal_5f8cb1dedf83b.pdf
SUSPICIOUS — normal_5f8cb1dedf83b.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
18a253970e8528ab4270054ccc804acdf9b766b8897c81850f37f697a30b51d4 - SHA-1:
248f1a188144634e3fb7e68d4df0ea96e6a4b7bf - MD5:
10231557fca6e6c1866aba70ce2334fe - ssdeep:
1536:4GF8pFx9uawrnNXKt7dut2QkrWOnvdGPXh5ndGA:VF8p79EnNXKt0t2QivdGPR1d9 - TLSH:
T10D339FF340ABDD4C3ACF7B079EEB104D654AD689613297A149CC3B6CD0B86ED6E10960 - Submitted as: normal_5f8cb1dedf83b.pdf
- File type: pdf · Size: 51040 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/67402b97-dbf7-4be3-9beb-70fa8c069641/66040369885.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=chemical+equations+synthesis+reactions+worksheet, https://uploads.strikinglycdn.com/files/67402b97-dbf7-4be3-9beb-70fa8c069641/66040369885.pdf, https://uploads.strikinglycdn.com/files/1744aed7-3579-407f-a971-28690951734d/41597252373.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=chemical+equations+synthesis+reactions+worksheet
- https://uploads.strikinglycdn.com/files/67402b97-dbf7-4be3-9beb-70fa8c069641/66040369885.pdf
- https://uploads.strikinglycdn.com/files/1744aed7-3579-407f-a971-28690951734d/41597252373.pdf
- https://uploads.strikinglycdn.com/files/de37f7c0-b876-4081-b940-45ee945cff29/xezodiminajulobaferoxutu.pdf
- https://uploads.strikinglycdn.com/files/280e933a-976a-421b-ab04-0dec340f7add/nufafu.pdf
- https://cdn.shopify.com/s/files/1/0431/5391/6065/files/best_heavy_armor_skyrim_unique.pdf
- https://cdn.shopify.com/s/files/1/0482/1788/2776/files/dovujilaxitaxofudok.pdf
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/irc_sp_108.pdf
- https://cdn.shopify.com/s/files/1/0435/1354/4863/files/korabuwibufiruxulimov.pdf
- https://uploads.strikinglycdn.com/files/cf0cc7ef-c30b-484d-80d8-fdd73422b038/21718393024.pdf
- https://uploads.strikinglycdn.com/files/0458812c-f50d-4f38-8fee-d8df165885b7/30319043991.pdf
- https://uploads.strikinglycdn.com/files/1b8b7462-00a7-428c-a38e-4f38a99b46f2/95988969892.pdf
- https://uploads.strikinglycdn.com/files/6b083c11-d455-496e-b237-e31c74fbc207/foribowamigago.pdf
- https://uploads.strikinglycdn.com/files/04d097be-6ee0-49a2-af22-d4a711a90b89/folezupilewipomunir.pdf
- https://uploads.strikinglycdn.com/files/f41668a3-0a94-4903-8504-4999ff13d2ab/wutulup.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/domovodibaposix.pdf
- https://ziripovopibew.weebly.com/uploads/1/3/0/8/130874468/aabca3c5af59.pdf
- https://uploads.strikinglycdn.com/files/6676513e-2099-413b-a2bc-2ae87edcb778/56007496425.pdf
- https://uploads.strikinglycdn.com/files/f161b775-7d78-40d9-ace3-4c7b1aa18d4a/24120536457.pdf
- https://uploads.strikinglycdn.com/files/53a0d81d-133d-4398-90c0-5ef3bb3704c3/pekujodojuwetoma.pdf
- https://uploads.strikinglycdn.com/files/ab26bf32-1052-4938-861a-2acbcfbcdf45/xotalav.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- guwomenod.weebly.com
- ziripovopibew.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report