SUSPICIOUS — normal_5f88d93a91942.pdf
SUSPICIOUS — normal_5f88d93a91942.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4bf9af6754cf33dd4a6a824680c40f6a1428fe74db65d5220e31516e251bee8b - SHA-1:
07b5cdeaa97bd00faf81ef4010333c38cc9a11b1 - MD5:
12ee2b7b7f2e18108ad1b6a7d1cfd502 - ssdeep:
768:KgGzpD7pEMwXriwW6qoLVQKyOMyQILjqEgb5ktMRwU5cyIEpJMfREXh38Lh+T:XGFfpEcdQMyzCb5EgyEJMyt8YT - TLSH:
T154329DF354ABED4C7A8B5F03BCAA0095548AD2486132D790498C7B6CD5BC6FEBE10960 - Submitted as: normal_5f88d93a91942.pdf
- File type: pdf · Size: 45226 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/765ddb05-67e0-4f80-a590-0d3c75d05cdc/wewobasiwotulewone.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=spiritual+books+pdf+free, https://cdn-cms.f-static.net/uploads/4367646/normal_5f88bd0b3ef41.pdf, https://cdn-cms.f-static.net/uploads/4366406/normal_5f878925bac38.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=spiritual+books+pdf+free
- https://cdn-cms.f-static.net/uploads/4367646/normal_5f88bd0b3ef41.pdf
- https://cdn-cms.f-static.net/uploads/4366406/normal_5f878925bac38.pdf
- https://cdn-cms.f-static.net/uploads/4369327/normal_5f88ca6a99c04.pdf
- https://site-1042670.mozfiles.com/files/1042670/36820577087.pdf
- https://site-1039174.mozfiles.com/files/1039174/47376655139.pdf
- https://cdn.shopify.com/s/files/1/0482/7575/1067/files/7950968219.pdf
- https://cdn.shopify.com/s/files/1/0491/9135/4534/files/rt_sports_app_apk.pdf
- https://cdn.shopify.com/s/files/1/0504/0855/4670/files/2020_jeep_liberty_manual_transmission_for_sale.pdf
- https://uploads.strikinglycdn.com/files/765ddb05-67e0-4f80-a590-0d3c75d05cdc/wewobasiwotulewone.pdf
- https://uploads.strikinglycdn.com/files/a000381e-08c7-46cb-8049-0d88ffa2d68d/12034046472.pdf
- https://uploads.strikinglycdn.com/files/f80b1c26-6835-46d2-8f99-411f64c52113/fazetezuloruzefatopik.pdf
- https://uploads.strikinglycdn.com/files/76828c2f-bd2c-4ca7-b2b8-a9a58808bcb3/belojukemu.pdf
- https://uploads.strikinglycdn.com/files/7ba9d1e9-b140-4038-8e00-ef8f9b3ca101/jederafolujopi.pdf
- https://uploads.strikinglycdn.com/files/68550e9d-8953-451f-8651-e3d7f50f680d/goleze.pdf
- https://uploads.strikinglycdn.com/files/35d99bc2-b388-4624-be31-364d7099fc70/24880400465.pdf
- https://site-1040041.mozfiles.com/files/1040041/puranas_english_translation.pdf
- https://site-1043177.mozfiles.com/files/1043177/vemigodurovemejewug.pdf
- https://site-1039174.mozfiles.com/files/1039174/38781126630.pdf
- https://site-1039875.mozfiles.com/files/1039875/6215897006.pdf
- https://site-1039150.mozfiles.com/files/1039150/fugurexo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1042670.mozfiles.com
- site-1039174.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1040041.mozfiles.com
- site-1043177.mozfiles.com
- site-1039875.mozfiles.com
- site-1039150.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report