SUSPICIOUS — normal_5f872c6d2ed78.pdf
SUSPICIOUS — normal_5f872c6d2ed78.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bd007723d452c461a0c416a33e265311100f882ad90c1f9e71cdc4444f97559d - SHA-1:
ff69edf3e49c4eb96df9aa7d598b309bf38cd6dc - MD5:
5348394984cec085150b74a095140e5b - ssdeep:
1536:JGFVp5fBvtOQuIv/r4uE5QBU596/bAFi84e:cFVp5fBvtQIv/8unBU596sFx - TLSH:
T1E5349EF350A3ED4CBACFAB135AAB1558909A9389713293A044C8776CC07C7FD6F40952 - Submitted as: normal_5f872c6d2ed78.pdf
- File type: pdf · Size: 52761 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/14a899f6-1335-4f8d-823b-fd24f6f27722/86188669760.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=android+sqlite+insert+from+select, https://cdn-cms.f-static.net/uploads/4366033/normal_5f872a00974ac.pdf, https://cdn-cms.f-static.net/uploads/4366033/normal_5f86f958d85ab.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=android+sqlite+insert+from+select
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f872a00974ac.pdf
- https://cdn-cms.f-static.net/uploads/4366033/normal_5f86f958d85ab.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f86f85a58c0e.pdf
- https://site-1043809.mozfiles.com/files/1043809/pimogi.pdf
- https://site-1038421.mozfiles.com/files/1038421/konulugevupitola.pdf
- https://site-1042734.mozfiles.com/files/1042734/20383666919.pdf
- https://site-1040242.mozfiles.com/files/1040242/4268388178.pdf
- https://site-1041695.mozfiles.com/files/1041695/41703032565.pdf
- https://uploads.strikinglycdn.com/files/14a899f6-1335-4f8d-823b-fd24f6f27722/86188669760.pdf
- https://uploads.strikinglycdn.com/files/728c42ab-7cb5-4cf2-983f-9c8bfe4bd1bc/sikutupuro.pdf
- https://site-1039846.mozfiles.com/files/1039846/81528854079.pdf
- https://site-1041188.mozfiles.com/files/1041188/53887283774.pdf
- https://uploads.strikinglycdn.com/files/cb319ef6-c897-4b45-bd20-bc0f90e50783/91918623277.pdf
- https://uploads.strikinglycdn.com/files/9d04aa7f-99f1-4b33-b814-a1a610621ff1/49741275447.pdf
- https://uploads.strikinglycdn.com/files/a084875d-446e-4673-82b3-c97004ba15a7/majesilavasovaketujesise.pdf
- https://uploads.strikinglycdn.com/files/16cdcb10-5fb3-4f60-9793-6da9a4ec7339/41945633658.pdf
- https://uploads.strikinglycdn.com/files/42b33f73-390a-4ec6-a209-3ac4d8ead4e1/84452858699.pdf
- https://site-1044300.mozfiles.com/files/1044300/41315285570.pdf
- https://site-1043939.mozfiles.com/files/1043939/87711213795.pdf
- https://site-1042770.mozfiles.com/files/1042770/64898518451.pdf
- https://site-1038715.mozfiles.com/files/1038715/33378739828.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- site-1043809.mozfiles.com
- site-1038421.mozfiles.com
- site-1042734.mozfiles.com
- site-1040242.mozfiles.com
- site-1041695.mozfiles.com
- uploads.strikinglycdn.com
- site-1039846.mozfiles.com
- site-1041188.mozfiles.com
- site-1044300.mozfiles.com
- site-1043939.mozfiles.com
- site-1042770.mozfiles.com
- site-1038715.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report