SUSPICIOUS — normal_5f872bd6de789.pdf
SUSPICIOUS — normal_5f872bd6de789.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
99c1d9e43eaaed27c11f1ce6e114d5a675695c19a9724ece5090885cbc0f9539 - SHA-1:
9fd8949fd5cbd9bc4e4a8fa454bf83dd679c454a - MD5:
926dee543f3dcf4a1535a7223d4f7b2b - ssdeep:
1536:LGF2p/y0fOtqIewNUW1gaDuJllndXzRc930GrOieEcf:qF2p/y0f5IewGW1mlldXzRcx0GKf - TLSH:
T19337C0F32097ED4C3A8A1F57AED61499B5CDD28DA07293A000CD6B6CC57C6EE6F10921 - Submitted as: normal_5f872bd6de789.pdf
- File type: pdf · Size: 75367 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/1b3374f4-0c0f-447f-a059-f20b5304f73a/4635388096.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/123?keyword=registratore+di+cassa+olivetti+nettuna+700+manuale, https://uploads.strikinglycdn.com/files/1b3374f4-0c0f-447f-a059-f20b5304f73a/4635388096.pdf, https://uploads.strikinglycdn.com/files/30282a7f-f6e6-457a-811a-11890a80ae84/fediwumujaza.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/123?keyword=registratore+di+cassa+olivetti+nettuna+700+manuale
- https://uploads.strikinglycdn.com/files/1b3374f4-0c0f-447f-a059-f20b5304f73a/4635388096.pdf
- https://uploads.strikinglycdn.com/files/30282a7f-f6e6-457a-811a-11890a80ae84/fediwumujaza.pdf
- https://uploads.strikinglycdn.com/files/fd20a71b-9524-4fa3-b254-19e591326f79/35620908321.pdf
- https://uploads.strikinglycdn.com/files/92b72f1c-6088-43ec-a346-6353c79cc985/xafitodet.pdf
- https://site-1036744.mozfiles.com/files/1036744/ximolubepazobesogesoli.pdf
- https://site-1038725.mozfiles.com/files/1038725/jubokolivojubodax.pdf
- https://site-1040373.mozfiles.com/files/1040373/sumowolunadenimakewugov.pdf
- https://site-1048453.mozfiles.com/files/1048453/97309873521.pdf
- https://uploads.strikinglycdn.com/files/0b35562f-16da-4901-991c-7147644371a4/renovafi.pdf
- https://uploads.strikinglycdn.com/files/5ca08559-49c9-47c7-9631-18edf6ab8fc0/16818542085.pdf
- https://uploads.strikinglycdn.com/files/8e9480dc-65eb-4c8a-941c-1ae863dbf9d7/saxanegumowosewivoxab.pdf
- https://cdn-cms.f-static.net/uploads/4366004/normal_5f871fddca4cd.pdf
- https://cdn-cms.f-static.net/uploads/4365639/normal_5f8704df9cde8.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f86f9d29deb5.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f870ac3868e2.pdf
- https://cdn-cms.f-static.net/uploads/4366625/normal_5f871c2d9ba09.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f8726511f2a3.pdf
- https://cdn-cms.f-static.net/uploads/4366375/normal_5f872b4f9c79b.pdf
- https://cdn-cms.f-static.net/uploads/4366637/normal_5f8720a452778.pdf
- https://cdn-cms.f-static.net/uploads/4366982/normal_5f872bcbe573c.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f8726fe21b14.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036744.mozfiles.com
- site-1038725.mozfiles.com
- site-1040373.mozfiles.com
- site-1048453.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report