SUSPICIOUS — normal_5f87042cf0296.pdf
SUSPICIOUS — normal_5f87042cf0296.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
72d8b96b12b814dc22e02e23fc5cdf177d0f36ab05df53c71586cddcf627e52a - SHA-1:
359f08c77ab3ea6a62b0ffb15a41d7daaa4ea4dc - MD5:
a8b77fc38c2d1d3303a34ec57961e1d0 - ssdeep:
768:9FgGzpDMpgZ4ZuldzpV53/MSa33BbfV4KQyA9UJ9MhItAUVm7TYCtBLQ:9WGFQpk4Zu/h3/2bA9UIhItAZ3pBLQ - TLSH:
T1BA33AEF350E7DD4C698BAB07AEFA11195049EB49A13257A450CC3B6CC07C7BDBE50940 - Submitted as: normal_5f87042cf0296.pdf
- File type: pdf · Size: 49076 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4365621/normal_5f86fb714acbc.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=glacier+national+park+guide+book, https://cdn-cms.f-static.net/uploads/4365621/normal_5f86fb714acbc.pdf, https://cdn-cms.f-static.net/uploads/4365612/normal_5f86fa042e521.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=glacier+national+park+guide+book
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f86fb714acbc.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f86fa042e521.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f87003e3a6f3.pdf
- https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/xefafimofaxeparekuji.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/domovodibaposix.pdf
- https://jemiwuwavaza.weebly.com/uploads/1/3/0/8/130814288/tigosorivibisakoxu.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/lanadez.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bamudepekepa_setumazowido.pdf
- https://uploads.strikinglycdn.com/files/46897710-b805-4597-a291-9969cf5aab9e/14052315211.pdf
- https://uploads.strikinglycdn.com/files/96417e31-b530-49d4-8d6d-c1af26a039d4/sajakovalomepawovozar.pdf
- https://uploads.strikinglycdn.com/files/fa3aa71c-5ad8-4768-b838-4b61eb038fc6/15152250643.pdf
- https://uploads.strikinglycdn.com/files/e3c36dbc-1b10-40e7-9a53-2080981db74c/julifeligozajazugis.pdf
- https://uploads.strikinglycdn.com/files/66c94a7e-af79-41ec-88cd-e364c54fa27c/lizonopunox.pdf
- https://uploads.strikinglycdn.com/files/45389ee6-ced3-484d-ae05-472224b8750e/savonamarinimid.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f6548e65e.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_5f86f57fd9627.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/duwivif.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/gosibokuvefuj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- mojivimimujovo.weebly.com
- guwomenod.weebly.com
- jemiwuwavaza.weebly.com
- vuxozajuje.weebly.com
- uploads.strikinglycdn.com
- genigudepa.weebly.com
- keniwuki.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report