SUSPICIOUS — 6ae36f3bd.pdf
SUSPICIOUS — 6ae36f3bd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
470f7608b0a769186e60cf1e437cb47e610cee1a139a7618ad8c05f6ba0200f8 - SHA-1:
6346ebf9bbc12b0515e7a673efa028c30b559548 - MD5:
43b1ed426d1a15e8ce55a0f86d87b1dc - ssdeep:
768:8vWgGzpDFFZcDHn5KOzbm+vjL9PWuRrv4/8zG6wiuEi/5JncUFpYFYZ6VY4KtlRK:yGFB+B9PWud884iY/TzroqMYVtUHHln - TLSH:
T10431AEF79157EC8D72CA6F136DA70058208AC68CA126D35418CC7B3DC5BC6BCAE54A71 - Submitted as: 6ae36f3bd.pdf
- File type: pdf · Size: 42705 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=how%20to%20use%20prepositions%20in%20english%20sentences%20pdf, https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/forobodarubulipik.pdf, https://cdn.shopify.com/s/files/1/0501/5666/7042/files/12208700409.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=how%20to%20use%20prepositions%20in%20english%20sentences%20pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/forobodarubulipik.pdf
- https://cdn.shopify.com/s/files/1/0501/5666/7042/files/12208700409.pdf
- https://cdn.shopify.com/s/files/1/0502/2570/9211/files/wosowaz.pdf
- https://uploads.strikinglycdn.com/files/593c7bd7-60da-4007-9e30-e4bcae644a35/nutrient_cycles_answers.pdf
- https://cdn.shopify.com/s/files/1/0266/9556/5499/files/96377139051.pdf
- https://uploads.strikinglycdn.com/files/b16116b2-6af4-48f5-928e-862e950872d9/vilenuwonininoledejakit.pdf
- https://cdn.shopify.com/s/files/1/0437/5199/7592/files/ace_the_bat_hound_first_appearance.pdf
- https://cdn.shopify.com/s/files/1/0268/8771/7035/files/workflow_diagram_tutorial.pdf
- https://cdn-cms.f-static.net/uploads/4412773/normal_5f977bc30ebb5.pdf
- https://cdn.shopify.com/s/files/1/0496/6458/9973/files/fagax.pdf
- https://cdn.shopify.com/s/files/1/0499/8411/0754/files/change_preferred_network_type_android.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- vilukenuxe.weebly.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report