MALICIOUS — 0401dccc50bde7.pdf
MALICIOUS — 0401dccc50bde7.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
6509c7ef9028478c4a7e22c0b8901b2e4826a753416f0c7ffd67210d40834f10 - SHA-1:
c690f0f89d10f573126cfac30b74d6310331962e - MD5:
9fa394678f8e55dd6d55523d3a886953 - ssdeep:
768:cgGzpD8poWZe0JzmXHdOq4s76EmuRNApo9ncawkkpj+R:5GFYp4Xk+6ARusncEkpj+R - TLSH:
T1D7306CF35493ED8C7B8B9B439DEA119A208AD688613697A044DD7B6CC47C2ED7F10860 - Submitted as: 0401dccc50bde7.pdf
- File type: pdf · Size: 37458 bytes
- Verdict: malicious (70/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://gettraff.ru/wb?keyword=asus%20h110m%20c, https://cdn.shopify.com/s/files/1/0478/7965/1494/files/xem_phim_hd_online_apk.pdf, https://cdn.shopify.com/s/files/1/0432/9344/2208/files/topugamofumuxisivokupefeb.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=asus%20h110m%20c
- https://cdn.shopify.com/s/files/1/0478/7965/1494/files/xem_phim_hd_online_apk.pdf
- https://cdn.shopify.com/s/files/1/0432/9344/2208/files/topugamofumuxisivokupefeb.pdf
- https://cdn.shopify.com/s/files/1/0433/9387/6118/files/ccloud_tv_guide_not_loading.pdf
- https://cdn.shopify.com/s/files/1/0432/0968/7208/files/12028271460.pdf
- https://cdn.shopify.com/s/files/1/0266/8888/0836/files/modeling_chemistry_unit_4_worksheet_2_answers.pdf
- https://uploads.strikinglycdn.com/files/059c8f62-6c13-486c-9a8e-b78d9b7513f4/3580707839.pdf
- https://uploads.strikinglycdn.com/files/1a538f6e-7ce3-43fb-9836-07fb2a6395c7/fosipakadimekukinilanatiw.pdf
- https://uploads.strikinglycdn.com/files/8dc04723-861b-48c7-be18-a641d9924e4e/45326808968.pdf
- https://uploads.strikinglycdn.com/files/2c7c050e-5071-4468-a6c5-ca3ee214d7c9/tatupivuwad.pdf
- https://uploads.strikinglycdn.com/files/953e9b2d-2c26-4438-a6ed-d3a88311d394/vesegozisagux.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/6533331.pdf
- https://rutaluxunenore.weebly.com/uploads/1/3/0/7/130740368/ruxixakukutego.pdf
- https://pumowurunumig.weebly.com/uploads/1/3/2/7/132740285/selanegadasadusokopu.pdf
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/venemawuj-noxaropuneze-nabadebotisi-susetidor.pdf
- https://gimejexoxixaza.weebly.com/uploads/1/3/1/8/131872185/wotareropajewub.pdf
- https://dimaxafazeza.weebly.com/uploads/1/3/1/4/131453031/nukexifepejisox.pdf
- https://cdn.shopify.com/s/files/1/0435/8737/1171/files/20278758748.pdf
- https://cdn.shopify.com/s/files/1/0483/2280/5913/files/lg_840g_tutorials.pdf
- https://site-1043805.mozfiles.com/files/1043805/30067601225.pdf
- https://site-1041295.mozfiles.com/files/1041295/widutobegunog.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- zesopupejilit.weebly.com
- rutaluxunenore.weebly.com
- pumowurunumig.weebly.com
- vekejuritikoj.weebly.com
- gimejexoxixaza.weebly.com
- dimaxafazeza.weebly.com
- site-1043805.mozfiles.com
- site-1041295.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report