SUSPICIOUS — 6febba2b6.pdf
SUSPICIOUS — 6febba2b6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
32532055660cac5e45206c8689e78556ecc8f332434140f687729bd9817e54bd - SHA-1:
6014aa4955ab98d30d4999994e2ab08b74f636ee - MD5:
d4c5e25a4ee5892d478c4b2eb33fba10 - ssdeep:
768:RgGzpDSpA8Icb/XRwh8p/NXEMYB+84aI5hXfvcQ+kEPt49HqyeWADKeyshzEoeXq:iGFWpZHfvcQ0POxe/DrxeXTkE/LWZuI - TLSH:
T183328EF74093EC4D7ACE9B0779AA119A6489C38D2037D79018C8766CD0BCAED7F11661 - Submitted as: 6febba2b6.pdf
- File type: pdf · Size: 47104 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=day%20r%20survival%20guide, https://cdn.shopify.com/s/files/1/0482/8486/0578/files/lite_star_mod_apk_download.pdf, https://cdn.shopify.com/s/files/1/0483/8264/0285/files/vuziwafagojevivepi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=day%20r%20survival%20guide
- https://cdn.shopify.com/s/files/1/0482/8486/0578/files/lite_star_mod_apk_download.pdf
- https://cdn.shopify.com/s/files/1/0483/8264/0285/files/vuziwafagojevivepi.pdf
- https://cdn.shopify.com/s/files/1/0439/0171/4587/files/8440641221.pdf
- https://cdn.shopify.com/s/files/1/0498/2626/7291/files/dictionnaire_des_faux_amis_franais-anglais.pdf
- https://cdn.shopify.com/s/files/1/0483/7510/3637/files/weed_spraying_risk_assessment.pdf
- https://cdn-cms.f-static.net/uploads/4368736/normal_5f887260721c5.pdf
- https://cdn-cms.f-static.net/uploads/4365998/normal_5f871123ce082.pdf
- https://cdn-cms.f-static.net/uploads/4380680/normal_5f8dc98b304d4.pdf
- https://s3.amazonaws.com/jamokaroxoj/noviminorufasabidupu.pdf
- https://s3.amazonaws.com/kavitokolezub/fonujirajid.pdf
- https://s3.amazonaws.com/davubewu/guvubudifevo.pdf
- https://s3.amazonaws.com/kavitokolezub/bolom.pdf
- https://cdn.shopify.com/s/files/1/0438/2212/1122/files/text_messages_online_android.pdf
- https://cdn.shopify.com/s/files/1/0484/0878/9150/files/doledavuxeka.pdf
- https://cdn.shopify.com/s/files/1/0484/6898/3969/files/manuale_istruzioni_tieni_il_conto_zucchetti.pdf
- https://cdn.shopify.com/s/files/1/0440/7725/2760/files/zerowiwokerad.pdf
- https://cdn.shopify.com/s/files/1/0266/8586/6167/files/lg_microwave_model_lmv2031st_manual.pdf
- https://cdn.shopify.com/s/files/1/0266/9087/9667/files/phantasus_arno_holz.pdf
- https://cdn.shopify.com/s/files/1/0476/7626/0518/files/42972013939.pdf
- https://cdn.shopify.com/s/files/1/0497/2940/5079/files/17822424130.pdf
- https://cdn.shopify.com/s/files/1/0437/1241/3847/files/33910373540.pdf
- https://cdn.shopify.com/s/files/1/0495/7647/6828/files/can_you_airdrop_from_iphone_to_android.pdf
- https://cdn.shopify.com/s/files/1/0467/8038/3385/files/download_design_home_apkpure.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report