SUSPICIOUS — normal_5fa52431936fb.pdf
SUSPICIOUS — normal_5fa52431936fb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c0e105def8fafdb8fdbd45c1bba174472cfbbab153c3701ffaf6998db5062d59 - SHA-1:
f5eabf0262e305ff52e31eacce4725a854d435ef - MD5:
ab538d55bba104454c42913500051274 - ssdeep:
3072:lF/gYz2CG00OcSQZp2N25jUBJi926EtSyn2lV:r4q2CG00OkZp2KwC5plV - TLSH:
T1B93BE0F355CBDDCCBA86AF83A8A6144C750AD6482222DB90508D763CC9FC2BD6F50D91 - Submitted as: normal_5fa52431936fb.pdf
- File type: pdf · Size: 106331 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4afe5765-b4b0-4f17-8a03-7e7c2f838835/19799605910.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffset.ru/123?keyword=marijuana+seeds+for+sale+usa+cheap, https://uploads.strikinglycdn.com/files/4afe5765-b4b0-4f17-8a03-7e7c2f838835/19799605910.pdf, https://uploads.strikinglycdn.com/files/1f81c530-54d9-48da-ac67-0dabd44d4894/vimoduwodenuf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffset.ru/123?keyword=marijuana+seeds+for+sale+usa+cheap
- https://uploads.strikinglycdn.com/files/4afe5765-b4b0-4f17-8a03-7e7c2f838835/19799605910.pdf
- https://uploads.strikinglycdn.com/files/1f81c530-54d9-48da-ac67-0dabd44d4894/vimoduwodenuf.pdf
- https://uploads.strikinglycdn.com/files/f3731b9a-122b-4644-ba07-81659b3da9f0/nepuvenoxa.pdf
- https://uploads.strikinglycdn.com/files/adab4492-df97-4619-89f7-b5b9def6a5c0/24343930632.pdf
- https://uploads.strikinglycdn.com/files/541a863c-23ff-459f-a3f3-36793877900c/zitixidivupefevamonibin.pdf
- https://uploads.strikinglycdn.com/files/53edaffe-0681-41e2-8cbb-9537836894ac/degejob.pdf
- https://uploads.strikinglycdn.com/files/f9912739-2084-4236-b2ad-4cda4fb15811/4845381496.pdf
- https://uploads.strikinglycdn.com/files/6442f868-5849-441e-94f4-b3bc2ea4f21a/68892897731.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/7904132.pdf
- https://uploads.strikinglycdn.com/files/665caa33-2cb6-4d7b-9396-d8a3fcf0c0cf/gamovawuguzawawepusam.pdf
- https://uploads.strikinglycdn.com/files/17aebf47-3c04-4541-9194-7778ca8db34c/fijukitetavotakibazasez.pdf
- https://s3.amazonaws.com/vekodupiwarobi/ascii_and_unicode_table.pdf
- https://uploads.strikinglycdn.com/files/9a84e5ff-09f7-475c-a985-761cffd3bd78/batusobo.pdf
- https://fikazimibugexu.weebly.com/uploads/1/3/4/5/134515259/9640037.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffset.ru
- uploads.strikinglycdn.com
- keniwuki.weebly.com
- s3.amazonaws.com
- fikazimibugexu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report