SUSPICIOUS — normal_5f8764513d974.pdf
SUSPICIOUS — normal_5f8764513d974.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2f54fa58964f495db1061bc2368d8e46163aea74f6884a847da2bec2bd8e34f8 - SHA-1:
55530a3e8d87902abadae782f0008f5ab02f9fe4 - MD5:
7e7146fce0cae6a2ef0571911c2f92a1 - ssdeep:
768:dhgGzpDhpow4WaLgHkGxfqxKRB1JHEztbZil1HC1IaLzpwC+UmJ3QeWH:oGF9ptf7FHaNeQ1IWB+ceWH - TLSH:
T1E1329FF310E7ED8C768A6F039EEB1168618AC78C6027966044C8766CD4B8AFD7F10D65 - Submitted as: normal_5f8764513d974.pdf
- File type: pdf · Size: 43934 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/09ae5acd-f6b8-458e-bdd2-eb51b696ec2e/lomabadudiwegezer.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=download+best+video+editor+for+android, https://uploads.strikinglycdn.com/files/09ae5acd-f6b8-458e-bdd2-eb51b696ec2e/lomabadudiwegezer.pdf, https://uploads.strikinglycdn.com/files/492275a2-2242-42d5-8239-6331afd44225/kugikuzez.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=download+best+video+editor+for+android
- https://uploads.strikinglycdn.com/files/09ae5acd-f6b8-458e-bdd2-eb51b696ec2e/lomabadudiwegezer.pdf
- https://uploads.strikinglycdn.com/files/492275a2-2242-42d5-8239-6331afd44225/kugikuzez.pdf
- https://uploads.strikinglycdn.com/files/6bb18a3f-b94d-4fa2-8b38-9b2b8b214b99/finuvid.pdf
- https://cdn-cms.f-static.net/uploads/4366308/normal_5f8752c3ae432.pdf
- https://cdn-cms.f-static.net/uploads/4366312/normal_5f875ed8756c5.pdf
- https://cdn-cms.f-static.net/uploads/4366048/normal_5f86fa9db6b07.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f870b1f5be8d.pdf
- https://uploads.strikinglycdn.com/files/03a709b2-c6d4-4500-b47f-0c082f43682c/8285804274.pdf
- https://uploads.strikinglycdn.com/files/33e41e9b-9e4b-486f-8d5f-5675b32ae6dc/vigefusep.pdf
- https://uploads.strikinglycdn.com/files/1e350e3b-c05b-4733-a175-c2b9e6681f21/62028055515.pdf
- https://uploads.strikinglycdn.com/files/9a8e17b7-eaad-4b44-b0ac-863ceea1e7a3/nanegunoroxaruzuvovutisi.pdf
- https://uploads.strikinglycdn.com/files/4fdba1f2-8c9b-4248-845e-2d414d424e9f/jezexomalada.pdf
- https://site-1048530.mozfiles.com/files/1048530/botedupanivavadef.pdf
- https://site-1048260.mozfiles.com/files/1048260/sesenogufosijaxuxaxiwameg.pdf
- https://site-1042348.mozfiles.com/files/1042348/26326750179.pdf
- https://site-1043246.mozfiles.com/files/1043246/moxugumofewoxowumofelale.pdf
- https://uploads.strikinglycdn.com/files/fa655059-4ff9-4638-8b2b-4609b3f62838/91107670661.pdf
- https://uploads.strikinglycdn.com/files/05b9e240-987a-4c41-bdfb-4152db565bd8/pobujese.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1048530.mozfiles.com
- site-1048260.mozfiles.com
- site-1042348.mozfiles.com
- site-1043246.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report