SUSPICIOUS — normal_5f872a3e0f063.pdf
SUSPICIOUS — normal_5f872a3e0f063.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
697cff8fb99d4edc9c4db8f80ddd0511d86b051c6aa0d3e3a82151c313c536da - SHA-1:
e7974f7ea8a411a83170040e475dc1bd6ab80c1c - MD5:
427d2151bbe1c71ed14348d89e65df25 - ssdeep:
768:zTgGzpDDpYU6t+hDo9PUwzqYcAmKsSp5Q2pvKEq9nDuJnxOWiabZf4afo8IAWIKm:wGFnpqttUEVskOdqZAafbIAWINfQK - TLSH:
T13A348DF31183DD8C7A8FAF53ADAA105D628AC7496132DB505588677CC17CAFC2E00BA5 - Submitted as: normal_5f872a3e0f063.pdf
- File type: pdf · Size: 53006 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a4ef2255-9e0b-4304-9b6e-603ae5d31d39/7996536755.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=sqlite+list+tables+android, https://uploads.strikinglycdn.com/files/a4ef2255-9e0b-4304-9b6e-603ae5d31d39/7996536755.pdf, https://uploads.strikinglycdn.com/files/40554f8e-c383-42d0-909e-f6ad0229bd31/daxiboparusugarezefu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=sqlite+list+tables+android
- https://uploads.strikinglycdn.com/files/a4ef2255-9e0b-4304-9b6e-603ae5d31d39/7996536755.pdf
- https://uploads.strikinglycdn.com/files/40554f8e-c383-42d0-909e-f6ad0229bd31/daxiboparusugarezefu.pdf
- https://uploads.strikinglycdn.com/files/c9b29ebb-c25d-458a-add3-3df3726137d8/takejug.pdf
- https://site-1036951.mozfiles.com/files/1036951/gakituzubek.pdf
- https://site-1042619.mozfiles.com/files/1042619/20302827503.pdf
- https://site-1039752.mozfiles.com/files/1039752/vepibiv.pdf
- https://site-1039279.mozfiles.com/files/1039279/bamomojikokaselifuzuzopuv.pdf
- https://cdn.shopify.com/s/files/1/0497/3694/1729/files/period_of_a_cos_graph.pdf
- https://cdn.shopify.com/s/files/1/0468/1511/7466/files/79815847247.pdf
- https://uploads.strikinglycdn.com/files/7b9ac737-9a42-4e06-b6c9-7216c63f4e78/govajalaredal.pdf
- https://uploads.strikinglycdn.com/files/f99af164-07c0-4812-8862-59c8f409f0b2/65297145926.pdf
- https://cdn.shopify.com/s/files/1/0497/5067/1514/files/wopab.pdf
- https://cdn.shopify.com/s/files/1/0501/6761/1542/files/types_of_bridges_for_teeth.pdf
- https://cdn.shopify.com/s/files/1/0434/3005/2005/files/free_google_play_redeem_codes_giveaway_without_human_verification.pdf
- https://cdn.shopify.com/s/files/1/0266/7580/6391/files/great_depression_era_deportations_apush.pdf
- https://cdn.shopify.com/s/files/1/0441/2761/7176/files/1997_ford_f150_4x4_owners_manual.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f87001ad74a6.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f87056412921.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f8721e235e1f.pdf
- https://cdn-cms.f-static.net/uploads/4366331/normal_5f871da773225.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f870c8b036a1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036951.mozfiles.com
- site-1042619.mozfiles.com
- site-1039752.mozfiles.com
- site-1039279.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report