SUSPICIOUS — 2b865de6ac17.pdf
SUSPICIOUS — 2b865de6ac17.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
4da56d486449ba2ced4861552628d286379e762aae972015f2bde5ef2749569a - SHA-1:
cbce71dce2ed1aeee401130bdaf1ce52d2b93237 - MD5:
e59fb78b5ccea54811d186945afbc48f - ssdeep:
1536:uGF4elEWzg4gsPHSxsr+5C593hSxlGuXrPFA:XF4elG47HSxsl/3hylGubP2 - TLSH:
T1BF339DF32097ED4D7A8F6B139EB711686489D68DA136DB50058C7B6CC4BC6BC3E10A60 - Submitted as: 2b865de6ac17.pdf
- File type: pdf · Size: 52239 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=tarot%20symbols%20history, https://cdn-cms.f-static.net/uploads/4366359/normal_5f87c0345371c.pdf, https://cdn-cms.f-static.net/uploads/4366344/normal_5f87c939510e1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=tarot%20symbols%20history
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f87c0345371c.pdf
- https://cdn-cms.f-static.net/uploads/4366344/normal_5f87c939510e1.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f86fb50559ad.pdf
- https://cdn-cms.f-static.net/uploads/4366660/normal_5f87c258dbdb8.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f874d32d1857.pdf
- https://cdn-cms.f-static.net/uploads/4365662/normal_5f876a715dfe7.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f8710f5d6ba9.pdf
- https://cdn-cms.f-static.net/uploads/4367911/normal_5f875a024da46.pdf
- https://cdn-cms.f-static.net/uploads/4365649/normal_5f8774751870f.pdf
- https://site-1038599.mozfiles.com/files/1038599/rujejimuwaxotowufi.pdf
- https://site-1043446.mozfiles.com/files/1043446/65826501209.pdf
- https://site-1037114.mozfiles.com/files/1037114/40642107061.pdf
- https://site-1043611.mozfiles.com/files/1043611/4601919726.pdf
- https://site-1037010.mozfiles.com/files/1037010/2364278150.pdf
- https://cdn.shopify.com/s/files/1/0483/6389/6995/files/section_18.4_entropy_and_free_energy_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0465/3989/9039/files/chicken_gizzard_recipes_slow_cooker.pdf
- https://cdn.shopify.com/s/files/1/0428/1552/0935/files/navy_instructor_manual.pdf
- https://cdn.shopify.com/s/files/1/0432/2253/2251/files/terrarium_tv_pro_apk_no_ads.pdf
- https://cdn.shopify.com/s/files/1/0497/9425/2961/files/university_neighborhood_high_school_basketball.pdf
- https://site-1039533.mozfiles.com/files/1039533/wijinataluz.pdf
- https://site-1040987.mozfiles.com/files/1040987/16733943553.pdf
- https://site-1044108.mozfiles.com/files/1044108/92208396354.pdf
- https://site-1039342.mozfiles.com/files/1039342/60467093852.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1038599.mozfiles.com
- site-1043446.mozfiles.com
- site-1037114.mozfiles.com
- site-1043611.mozfiles.com
- site-1037010.mozfiles.com
- cdn.shopify.com
- site-1039533.mozfiles.com
- site-1040987.mozfiles.com
- site-1044108.mozfiles.com
- site-1039342.mozfiles.com
- www.egroups.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report