SUSPICIOUS — ec5bf50.pdf
SUSPICIOUS — ec5bf50.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
0ade77d29f8a39596212031944090790c4cb800e2d664ecc1a921a7e08479111 - SHA-1:
cedec5fc85b344945aeffeaa861e1b587c5afa5e - MD5:
f41f554155cbadd8c3a972b8f57eb75d - ssdeep:
768:AgGzpD5pKDIHu5VbC85fPUy79rGZg3vq5EQhXM1/vTBqczW0UsBN3uUfPu3Fj4XZ:NGFlpE1i5Rh81X0czW0zP3uUfPu3Fj4p - TLSH:
T166318DF34093EC4D7A8F5B57AEAA119D644EC3C9B122EA5040C87B2DE47C9ED7E00961 - Submitted as: ec5bf50.pdf
- File type: pdf · Size: 42920 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=fisher%20body%20service%20manual, https://cdn.shopify.com/s/files/1/0496/3159/2597/files/trek_800_sport_specs.pdf, https://cdn.shopify.com/s/files/1/0484/4299/8938/files/john_deere_pedal_tractor_values.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=fisher%20body%20service%20manual
- https://cdn.shopify.com/s/files/1/0496/3159/2597/files/trek_800_sport_specs.pdf
- https://cdn.shopify.com/s/files/1/0484/4299/8938/files/john_deere_pedal_tractor_values.pdf
- https://cdn.shopify.com/s/files/1/0430/0183/9769/files/fobaju.pdf
- https://cdn.shopify.com/s/files/1/0430/3162/5882/files/www_bodyfitsuperstore_com_hcg_diet_injections.pdf
- https://site-1042018.mozfiles.com/files/1042018/36410095758.pdf
- https://site-1040794.mozfiles.com/files/1040794/2169662577.pdf
- https://site-1041862.mozfiles.com/files/1041862/kiwetozap.pdf
- https://cdn.shopify.com/s/files/1/0434/4938/5126/files/dremel_polishing_kit.pdf
- https://cdn.shopify.com/s/files/1/0430/3582/0185/files/intro_to_moles_worksheet_chemquest_30.pdf
- https://cdn.shopify.com/s/files/1/0432/5418/6146/files/6987250098.pdf
- https://cdn.shopify.com/s/files/1/0480/9637/9044/files/botivawibosetejak.pdf
- https://uploads.strikinglycdn.com/files/3d17c57d-6cdc-4ac5-99bb-c1c43108a58b/33178036580.pdf
- https://uploads.strikinglycdn.com/files/fa349785-7142-4f7c-8c4d-0003b9f60e6b/59240309307.pdf
- https://uploads.strikinglycdn.com/files/35a2d702-9b53-49cc-ad9f-2bec2081563f/nonulubox.pdf
- https://uploads.strikinglycdn.com/files/dc587e43-c191-4655-abb3-287b043ced78/24178999182.pdf
- https://uploads.strikinglycdn.com/files/3f67810e-7a3e-44ab-9e04-f2da569e91f4/39796099508.pdf
- https://cdn-cms.f-static.net/uploads/4366377/normal_5f870e9898f04.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f86f84941a1d.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f86f8737db67.pdf
- https://cdn-cms.f-static.net/uploads/4366018/normal_5f8711329b0a8.pdf
- https://site-1043669.mozfiles.com/files/1043669/53479473569.pdf
- https://site-1039922.mozfiles.com/files/1039922/vejaduvotefejewuvis.pdf
- https://site-1042359.mozfiles.com/files/1042359/xekapekado.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1042018.mozfiles.com
- site-1040794.mozfiles.com
- site-1041862.mozfiles.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1043669.mozfiles.com
- site-1039922.mozfiles.com
- site-1042359.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report