SUSPICIOUS — normal_5f894c25569b6.pdf
SUSPICIOUS — normal_5f894c25569b6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8bef81abf47e104ac9125a6e6f8d6be262917fc2e7771ba55e64f661cc0989cf - SHA-1:
2c5c699db3f7435901d63c09087320067401b8b6 - MD5:
9be644d80d62181362f6b0d084f90f6f - ssdeep:
1536:8GFrpcQGWQbV5O/Kn9S01Lne1nCdWxQgbKq:ZFrpzUV6Kn9+lC+x - TLSH:
T18D339FF310A7DD4C7B8AAB036EE62069654AD3887032DAA104CC636DD17C6FD7E11A60 - Submitted as: normal_5f894c25569b6.pdf
- File type: pdf · Size: 52170 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/48c40171-ae1c-4f09-b173-67f598543048/sikurojezinawotabop.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=ulala+idle+adventure+mod+apk+happymod, https://uploads.strikinglycdn.com/files/2edb2952-8006-4174-b97c-c4c0c9427595/61986333155.pdf, https://uploads.strikinglycdn.com/files/46dd45fd-393b-4556-aab1-936f04def56b/fusasub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=ulala+idle+adventure+mod+apk+happymod
- https://uploads.strikinglycdn.com/files/2edb2952-8006-4174-b97c-c4c0c9427595/61986333155.pdf
- https://uploads.strikinglycdn.com/files/46dd45fd-393b-4556-aab1-936f04def56b/fusasub.pdf
- https://uploads.strikinglycdn.com/files/6b5e9734-4a3c-4c99-b0ba-c00572b0c73f/vodobimo.pdf
- https://uploads.strikinglycdn.com/files/3687d950-fca4-4237-b9d9-c76816c959e4/ragamakosimevarot.pdf
- https://uploads.strikinglycdn.com/files/804f5faa-765a-475f-afcf-5373fb7289ec/jogafuwudum.pdf
- https://cdn.shopify.com/s/files/1/0266/7783/7997/files/xitituj.pdf
- https://cdn.shopify.com/s/files/1/0498/2741/4171/files/los_anunnaki_libro.pdf
- https://uploads.strikinglycdn.com/files/48c40171-ae1c-4f09-b173-67f598543048/sikurojezinawotabop.pdf
- https://uploads.strikinglycdn.com/files/f076893e-3927-4f68-a5b8-70dacbc8f2b7/1664962684.pdf
- https://uploads.strikinglycdn.com/files/7bbe6b4c-5d86-43f8-b100-73216ab16232/53717077877.pdf
- https://uploads.strikinglycdn.com/files/c85d804f-a4d7-44b3-9e27-842ccbd35a48/kegumewadugikora.pdf
- https://cdn.shopify.com/s/files/1/0434/4414/2245/files/wills_eye_manual_espaol.pdf
- https://cdn.shopify.com/s/files/1/0477/1744/9884/files/the_field_book_of_ponds_and_streams.pdf
- https://cdn.shopify.com/s/files/1/0434/6550/6966/files/30752444440.pdf
- https://cdn.shopify.com/s/files/1/0477/0391/6710/files/28937087472.pdf
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f8745397464e.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_5f87004d9e9d4.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f888c300dbdb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report