SUSPICIOUS — a8c606b473.pdf
SUSPICIOUS — a8c606b473.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
6d8c374b34672d7c37c6ea90b5165c9654cfd5271bdd3d65bff5c5726cf91aa0 - SHA-1:
aaab49a1849c335ecb08741c5f4aff420b92ebcd - MD5:
15c1eb1bf2a078041b1bb629b183bc49 - ssdeep:
768:LgGzpD5px8btXTGI9dgZSXTS6/e2Z+0ZLUXt+NqBwEGbPsve7D58EoXN:0GF9psnmgWcNqBw9bPue7D58X9 - TLSH:
T189328DF310A7DD8C2E869F839DAB0295A08AD7893232E760449C773CC4B85EE7F50951 - Submitted as: a8c606b473.pdf
- File type: pdf · Size: 43818 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=minecraft%20premiumsuz%20hexxit%20nas%C4%B1l%20in, https://cdn.shopify.com/s/files/1/0483/6802/5751/files/pvz_2_pak_apk.pdf, https://cdn.shopify.com/s/files/1/0436/5916/5849/files/11989743736.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=minecraft%20premiumsuz%20hexxit%20nas%C4%B1l%20in
- https://cdn.shopify.com/s/files/1/0483/6802/5751/files/pvz_2_pak_apk.pdf
- https://cdn.shopify.com/s/files/1/0436/5916/5849/files/11989743736.pdf
- https://cdn.shopify.com/s/files/1/0498/0195/3442/files/combine_multiple_word_files_into.pdf
- https://cdn.shopify.com/s/files/1/0482/7250/7044/files/pagelomosesafaduxalejal.pdf
- https://cdn.shopify.com/s/files/1/0493/1167/8623/files/19944187794.pdf
- https://cdn.shopify.com/s/files/1/0488/2310/7749/files/before_i_formed_you_in_the_womb_psalm_kjv.pdf
- https://cdn.shopify.com/s/files/1/0500/0436/1366/files/melikamomop.pdf
- https://site-1039251.mozfiles.com/files/1039251/55842207665.pdf
- https://site-1039414.mozfiles.com/files/1039414/lofurevi.pdf
- https://site-1041076.mozfiles.com/files/1041076/fupilimefomufepiwa.pdf
- https://nasinapalu.weebly.com/uploads/1/3/0/7/130739684/letabumu.pdf
- https://buluzuzumaz.weebly.com/uploads/1/3/1/6/131636727/1692507.pdf
- https://cdn-cms.f-static.net/uploads/4365580/normal_5f86f5b74122a.pdf
- https://cdn-cms.f-static.net/uploads/4366306/normal_5f8710b0ac055.pdf
- https://cdn-cms.f-static.net/uploads/4365628/normal_5f8702d475109.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f870dbca26b8.pdf
- https://uploads.strikinglycdn.com/files/acc50348-1522-4c77-982a-1472ca707a66/visalipej.pdf
- https://uploads.strikinglycdn.com/files/a70c4c80-6ef4-473f-a9ff-7e6152756675/pixolimajixoromalajujetu.pdf
- https://uploads.strikinglycdn.com/files/ee33416c-b355-4a58-9ec3-468078ea1fcd/pixebiwar.pdf
- https://uploads.strikinglycdn.com/files/84abaf70-be30-47a7-bedf-45eff0b5bf09/68230990912.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1039251.mozfiles.com
- site-1039414.mozfiles.com
- site-1041076.mozfiles.com
- nasinapalu.weebly.com
- buluzuzumaz.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report