SUSPICIOUS — 9b18cd795bd.pdf
SUSPICIOUS — 9b18cd795bd.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a35faef1c2a9258497d840a25696ed015c274d5f311fbaf84fde3744e17e3f1d - SHA-1:
949f50573b7ec8a55bc928dfb742b8ac16517df5 - MD5:
d84cc68885e9fcfbd6fd1a3460b26f59 - ssdeep:
768:AgGzpDjpg588AseuUZycJihWad+NNnjaPh6efAZGrzvGMBff3InFc+8TywX74+/+:NGFfpgJeCbAUXvFB3YnFEywX1+IAz - TLSH:
T1ED347CF34057ED4D3B8B7B83ADA71099645AC38962229B9045CC77BCD43C6AC7F20A61 - Submitted as: 9b18cd795bd.pdf
- File type: pdf · Size: 56390 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=guardian%20by%20petsafe%20anti-bark%20collar%20reviews, https://site-1036640.mozfiles.com/files/1036640/81121175641.pdf, https://site-1038376.mozfiles.com/files/1038376/gisitosezaxisemedif.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=guardian%20by%20petsafe%20anti-bark%20collar%20reviews
- https://site-1036640.mozfiles.com/files/1036640/81121175641.pdf
- https://site-1038376.mozfiles.com/files/1038376/gisitosezaxisemedif.pdf
- https://site-1041284.mozfiles.com/files/1041284/kulekanekenateg.pdf
- https://site-1038998.mozfiles.com/files/1038998/74346189535.pdf
- https://cdn.shopify.com/s/files/1/0433/1136/6309/files/66486305061.pdf
- https://cdn.shopify.com/s/files/1/0432/7263/4536/files/sunnah_book.pdf
- https://cdn.shopify.com/s/files/1/0497/9074/6785/files/wish_payment_issue.pdf
- https://cdn.shopify.com/s/files/1/0430/5498/9466/files/coleman_mach_thermostat_manual.pdf
- https://cdn.shopify.com/s/files/1/0437/4256/0407/files/88855920163.pdf
- https://cdn.shopify.com/s/files/1/0485/7446/4160/files/the_lost_mariner_case_study.pdf
- https://cdn.shopify.com/s/files/1/0465/1014/5694/files/xadubotumibebi.pdf
- https://cdn.shopify.com/s/files/1/0431/8868/2915/files/vojomekaxezunivono.pdf
- https://cdn.shopify.com/s/files/1/0483/3509/3911/files/kubuxatixutenolisaxov.pdf
- https://cdn.shopify.com/s/files/1/0481/5074/1153/files/the_emulator_zone_pcsx2.pdf
- https://cdn.shopify.com/s/files/1/0500/0436/1366/files/granger_middle_school_supply_list.pdf
- https://cdn.shopify.com/s/files/1/0460/7587/1396/files/dokalomemefefevizidaki.pdf
- https://cdn.shopify.com/s/files/1/0459/1249/0133/files/download_hack_clash_of_clans_android_apk_unlimited_gems.pdf
- https://cdn.shopify.com/s/files/1/0438/0898/1153/files/12009688534.pdf
- https://cdn-cms.f-static.net/uploads/4366340/normal_5f870edebfa55.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f872b5da7c69.pdf
- https://cdn-cms.f-static.net/uploads/4366646/normal_5f873346664e7.pdf
- https://site-1042940.mozfiles.com/files/1042940/likatonanodopogawesejako.pdf
- https://site-1038863.mozfiles.com/files/1038863/89033112281.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- site-1036640.mozfiles.com
- site-1038376.mozfiles.com
- site-1041284.mozfiles.com
- site-1038998.mozfiles.com
- cdn.shopify.com
- cdn-cms.f-static.net
- site-1042940.mozfiles.com
- site-1038863.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report