MALICIOUS — 6b41f42d23aeba.pdf
MALICIOUS — 6b41f42d23aeba.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
9775f2d67abcf3190492e0467e01e47d1aac33fbeec65b476dd8a7518fa5af7a - SHA-1:
f2aa5afb313ddd45ff3b57afa94e87974e0f9942 - MD5:
d05d90a70b7e260f181044ae0537e949 - ssdeep:
768:akgGzpDZpGraPJK58JFE8Wt2r/Lq5VwaaBIG33QoqXIeyN7d1w+SI5SD:6GFNpGV5PaB333QoxesJ2LI5SD - TLSH:
T123329EF3009BEC8C7A9A9F436DBB115A3095D3897136926418DC372CD4BCBED6E10A61 - Submitted as: 6b41f42d23aeba.pdf
- File type: pdf · Size: 43625 bytes
- Verdict: malicious (70/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://ggtraff.ru/wb?keyword=lilo%20and%20stitch%203%20full%20movie%20english, https://cdn.shopify.com/s/files/1/0440/7777/7061/files/how_to_upload_image_using_retrofit_android.pdf, https://cdn.shopify.com/s/files/1/0498/9331/0631/files/7059380717.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=lilo%20and%20stitch%203%20full%20movie%20english
- https://cdn.shopify.com/s/files/1/0440/7777/7061/files/how_to_upload_image_using_retrofit_android.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/7059380717.pdf
- https://cdn.shopify.com/s/files/1/0497/5624/2074/files/the_girl_from_ipanema_chords.pdf
- https://cdn.shopify.com/s/files/1/0478/4173/8911/files/concepts_of_independence_jobs.pdf
- https://cdn.shopify.com/s/files/1/0433/4105/4105/files/lalexema.pdf
- https://uploads.strikinglycdn.com/files/f34c89ee-23e3-4c90-a4ae-4d5b87bee0a3/muwimojunaruxijonozugita.pdf
- https://uploads.strikinglycdn.com/files/2e3dce78-0b4c-40d0-aeff-983e7dcb2b55/28661813098.pdf
- https://uploads.strikinglycdn.com/files/ca4a453b-3648-400e-b4ee-5c98da34e7b0/bekuv.pdf
- https://cdn.shopify.com/s/files/1/0266/8203/2318/files/50277112026.pdf
- https://cdn.shopify.com/s/files/1/0438/8395/4328/files/49352995916.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/33869410644.pdf
- https://cdn.shopify.com/s/files/1/0433/0517/3147/files/adding_and_subtracting_radical_expressions_worksheet_doc.pdf
- https://cdn.shopify.com/s/files/1/0499/8309/4934/files/16044830465.pdf
- https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/kemofopomekewuniw.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/ligewajinaxi.pdf
- https://tegugozitofo.weebly.com/uploads/1/3/0/8/130874592/930e76ac1f871.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- mefemanodi.weebly.com
- guwomenod.weebly.com
- tegugozitofo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report