SUSPICIOUS — normal_5f874f2c9933a.pdf
SUSPICIOUS — normal_5f874f2c9933a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7422c14347dd151bcd08115e96a7e93f33a75afa6fb3bbd0ef29f6ea4a32752a - SHA-1:
9760cbf98359198377efe3c0e39f333479df3ebe - MD5:
c8487e5bbff61386a76f709b1198e6a1 - ssdeep:
768:BgGzpDQpPGJetdlogqgLAHxoJJ+cbpDtx+4C9vPZXegfcjz6Qm7rP:yGFkppJdtx+4C9HZOxm7rP - TLSH:
T16232AFF32157EC8C3A866B47ADB61199518ACB8D6133A260508C362CD1BCFFD7E50A31 - Submitted as: normal_5f874f2c9933a.pdf
- File type: pdf · Size: 43372 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9d32f2b1-48a1-4ebd-99e7-23b16a809f5f/seburoxazofanu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=tv+guide+los+angeles+no+cable, https://cdn-cms.f-static.net/uploads/4367621/normal_5f874909b6cac.pdf, https://cdn-cms.f-static.net/uploads/4366015/normal_5f86fedf98283.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/123?keyword=tv+guide+los+angeles+no+cable
- https://cdn-cms.f-static.net/uploads/4367621/normal_5f874909b6cac.pdf
- https://cdn-cms.f-static.net/uploads/4366015/normal_5f86fedf98283.pdf
- https://cdn-cms.f-static.net/uploads/4366304/normal_5f87308f4d569.pdf
- https://cdn.shopify.com/s/files/1/0438/8107/0747/files/11658938343.pdf
- https://site-1039398.mozfiles.com/files/1039398/gusew.pdf
- https://site-1043938.mozfiles.com/files/1043938/14834825786.pdf
- https://cdn.shopify.com/s/files/1/0433/1533/1227/files/80237637255.pdf
- https://cdn.shopify.com/s/files/1/0438/3296/7318/files/chinese_zodiac_lesson_plan.pdf
- https://uploads.strikinglycdn.com/files/50eaf03d-c47e-4b4b-8b53-788847845c93/37152050151.pdf
- https://uploads.strikinglycdn.com/files/f3392839-1e33-4ef1-852e-f5dadf21197d/vunapebivuwaneluzunetuk.pdf
- https://uploads.strikinglycdn.com/files/9d32f2b1-48a1-4ebd-99e7-23b16a809f5f/seburoxazofanu.pdf
- https://uploads.strikinglycdn.com/files/fbfc835c-c56e-4e63-93b5-8b766c87554f/nijobasevunom.pdf
- https://cdn.shopify.com/s/files/1/0480/6964/0356/files/wright_brothers_david_mccullough.pdf
- https://cdn.shopify.com/s/files/1/0483/4315/4841/files/59178429596.pdf
- https://cdn.shopify.com/s/files/1/0488/3949/1749/files/24632329801.pdf
- https://cdn.shopify.com/s/files/1/0432/6214/8763/files/2520309074.pdf
- https://cdn.shopify.com/s/files/1/0481/7397/3671/files/rifojigaj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1039398.mozfiles.com
- site-1043938.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report