SUSPICIOUS — normal_5f870afe6daaa.pdf
SUSPICIOUS — normal_5f870afe6daaa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fe9044f1324aec29d0698fc32a4eb387d5ba4133d89b9900a6a0dfdd333ec7ca - SHA-1:
6730f29423e2cb4ef3c3d863c6e7117f0e7b0675 - MD5:
41498c51b182c8a8f0cdc162a419a436 - ssdeep:
768:NgGzpD0Xp/eCxCfSKdmTHEQa7ULlofT031VdrDNiY+lz6yd7EWbBLz:uGFKpZmDmTkr2h1VdrGlz6kzBLz - TLSH:
T123326CF75087EE4C7A8FBB079EE70159518AC3896132D7904888676DD4BCAFD2E10E20 - Submitted as: normal_5f870afe6daaa.pdf
- File type: pdf · Size: 44323 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f0761fa4-6376-418b-8ddb-d4a61ecc231a/93685713741.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/123?keyword=data+transfer+instructions+of+8086+with+examples, https://uploads.strikinglycdn.com/files/f0761fa4-6376-418b-8ddb-d4a61ecc231a/93685713741.pdf, https://uploads.strikinglycdn.com/files/fff31058-553c-48bc-8245-f78f57d54672/kogudo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/123?keyword=data+transfer+instructions+of+8086+with+examples
- https://uploads.strikinglycdn.com/files/f0761fa4-6376-418b-8ddb-d4a61ecc231a/93685713741.pdf
- https://uploads.strikinglycdn.com/files/fff31058-553c-48bc-8245-f78f57d54672/kogudo.pdf
- https://uploads.strikinglycdn.com/files/7ff158c7-2f4e-44b7-8440-eaf43a58b706/tasoraporefigifowas.pdf
- https://uploads.strikinglycdn.com/files/49575754-4a59-4fce-8e45-a066ca7e344f/28359948478.pdf
- https://uploads.strikinglycdn.com/files/35d255f2-ef42-4eb0-b065-e8be9082f91c/zuravaridizoku.pdf
- https://site-1037227.mozfiles.com/files/1037227/gesifonodulirowobuze.pdf
- https://site-1037274.mozfiles.com/files/1037274/85870510713.pdf
- https://site-1043601.mozfiles.com/files/1043601/jiregezijetesomegizikepun.pdf
- https://site-1037164.mozfiles.com/files/1037164/pugisuferiminujela.pdf
- https://site-1042779.mozfiles.com/files/1042779/sevewaxadamogafakowoj.pdf
- https://site-1041598.mozfiles.com/files/1041598/62375669483.pdf
- https://site-1041932.mozfiles.com/files/1041932/63348340958.pdf
- https://uploads.strikinglycdn.com/files/ca1d7d41-7fa2-4616-8079-b66273559411/nofibanofinonedemewut.pdf
- https://uploads.strikinglycdn.com/files/fa3d24d4-e7d7-4d94-91f5-654ed82eb6fe/3702056410.pdf
- https://site-1044264.mozfiles.com/files/1044264/86385214136.pdf
- https://site-1036829.mozfiles.com/files/1036829/sulabipatizoxigogufew.pdf
- https://site-1042025.mozfiles.com/files/1042025/35420514073.pdf
- https://site-1036982.mozfiles.com/files/1036982/kinote.pdf
- https://site-1038851.mozfiles.com/files/1038851/palavoxutokili.pdf
- https://uploads.strikinglycdn.com/files/bb250987-ac83-40ac-9d96-76f60698dd1a/32568536376.pdf
- https://uploads.strikinglycdn.com/files/4a5bff72-572d-4737-ba46-8c2b1f544bfc/newevevinizakapebive.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1037227.mozfiles.com
- site-1037274.mozfiles.com
- site-1043601.mozfiles.com
- site-1037164.mozfiles.com
- site-1042779.mozfiles.com
- site-1041598.mozfiles.com
- site-1041932.mozfiles.com
- site-1044264.mozfiles.com
- site-1036829.mozfiles.com
- site-1042025.mozfiles.com
- site-1036982.mozfiles.com
- site-1038851.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report