SUSPICIOUS — 947c01d8c12.pdf
SUSPICIOUS — 947c01d8c12.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a1d4c01ac0ff8e58c13393b23556ae8efcd5b388dcbc02c01cef7245f078c009 - SHA-1:
7f606ebc0fa19498c578b11ee6643ef41c1376c3 - MD5:
c121a009e3e57cd417a832209d422f15 - ssdeep:
768:dgGzpDNp00+hA3iZkZQQAL4Vr7dKGD79Nl5gnjO9+kOd8rYAQNOeVhycgkWxF/kY:eGFRp0CKC+kOd8kAQN57ycxt82xM - TLSH:
T151339EF31047DD8D3A8BAB13FD9B11989589D3892037EB9014887B2CD4B8AFD6E10B51 - Submitted as: 947c01d8c12.pdf
- File type: pdf · Size: 48017 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=avatar:%20the%20last%20airbender%20season%202%20episode%2019, https://cdn.shopify.com/s/files/1/0500/3267/2918/files/new_testament_manual_lds.pdf, https://cdn.shopify.com/s/files/1/0432/0513/2456/files/transverse_waves_worksheet_key.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=avatar:%20the%20last%20airbender%20season%202%20episode%2019
- https://cdn.shopify.com/s/files/1/0500/3267/2918/files/new_testament_manual_lds.pdf
- https://cdn.shopify.com/s/files/1/0432/0513/2456/files/transverse_waves_worksheet_key.pdf
- https://cdn.shopify.com/s/files/1/0484/7134/3266/files/zerudod.pdf
- https://cdn.shopify.com/s/files/1/0266/8648/8767/files/foxit_reader_ubuntu.pdf
- https://cdn.shopify.com/s/files/1/0500/5043/3194/files/82075792104.pdf
- https://cdn-cms.f-static.net/uploads/4365653/normal_5f87ddf6428cf.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f86f46e822b0.pdf
- https://cdn.shopify.com/s/files/1/0485/0715/8690/files/bawoxaxobeluwesafikura.pdf
- https://cdn.shopify.com/s/files/1/0501/2199/8496/files/18891536555.pdf
- https://cdn.shopify.com/s/files/1/0268/8253/9698/files/51758230329.pdf
- https://cdn.shopify.com/s/files/1/0440/1666/4734/files/doctor_who_wallpaper_android.pdf
- https://cdn.shopify.com/s/files/1/0435/8812/4830/files/nejejimijij.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/8282837.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/sobibizagavubuna.pdf
- https://uploads.strikinglycdn.com/files/c9640e87-5146-463a-a612-57aa2ca1d343/96550095377.pdf
- https://uploads.strikinglycdn.com/files/5cae1f48-0727-4d0f-858e-480899b93a5d/zetefobuseruvitunujonada.pdf
- https://uploads.strikinglycdn.com/files/cb8cbce0-a818-4956-89dc-7ed5068a40d6/nisoma.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f880aa3960eb.pdf
- https://cdn-cms.f-static.net/uploads/4367290/normal_5f88f0ac03cdd.pdf
- https://cdn-cms.f-static.net/uploads/4368772/normal_5f88dc931f130.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- tavumake.weebly.com
- jamuseramomuf.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report