SUSPICIOUS — normal_5f9f460e2613e.pdf
SUSPICIOUS — normal_5f9f460e2613e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
aaf23e968633faecc67916e18204ee008f2d0e1dd32886850f130ea5b5da1815 - SHA-1:
832095e23bd0d0a85b39b57ef7c9957434702961 - MD5:
9317f36b8f4389c8c3feab058cacc82a - ssdeep:
768:itgGzpDXimo7sJ/yozjbQChQaxsVs7HpZ3fsMnu+dH59aB0LeGLhUa8KlRPOzLW:hGF7e4HcCh9qVYXi4HleAUjKlVOzK - TLSH:
T13E34AFF3919BCC8C3A8BAB176FE65194B046A78C24339A9150C4722CC8BC6FC7F51961 - Submitted as: normal_5f9f460e2613e.pdf
- File type: pdf · Size: 55098 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/be3a4110-9740-47af-a9bf-5476f8ac11a8/85335979842.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=download+showbox+app+for+android+phone, https://uploads.strikinglycdn.com/files/be3a4110-9740-47af-a9bf-5476f8ac11a8/85335979842.pdf, https://uploads.strikinglycdn.com/files/f8cf287c-b672-4fab-bc14-f9bb20da288a/liburuxinoxavabokafewap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=download+showbox+app+for+android+phone
- https://s3.amazonaws.com/mexesazaxasa/gate_city_funeral_home_obituaries.pdf
- https://s3.amazonaws.com/felasorarabipis/35679645598.pdf
- https://uploads.strikinglycdn.com/files/be3a4110-9740-47af-a9bf-5476f8ac11a8/85335979842.pdf
- https://uploads.strikinglycdn.com/files/f8cf287c-b672-4fab-bc14-f9bb20da288a/liburuxinoxavabokafewap.pdf
- https://uploads.strikinglycdn.com/files/92954bbd-7ce4-48e7-ac69-0ff5cdb1b62a/jawuvukuv.pdf
- https://cdn-cms.f-static.net/uploads/4388173/normal_5f9cd496cce45.pdf
- https://uploads.strikinglycdn.com/files/9134a079-22ad-4ecc-9157-6f62a1f299f9/xevikagufemezomujodikabaw.pdf
- https://uploads.strikinglycdn.com/files/9334dc48-b754-4683-bc0d-b8a43b83e991/94527945279.pdf
- https://cdn-cms.f-static.net/uploads/4449990/normal_5f9f3a9f137f6.pdf
- https://cdn-cms.f-static.net/uploads/4388041/normal_5f8def134ad42.pdf
- https://s3.amazonaws.com/legenapi/a_history_of_narrative_film_4th_edition_free.pdf
- https://uploads.strikinglycdn.com/files/a781437b-146a-4964-8685-adf387818e8a/39515164228.pdf
- https://s3.amazonaws.com/vidadaviwal/kezafi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report