MALICIOUS — 6f3fe19.pdf
MALICIOUS — 6f3fe19.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ae3eb0eea12852804396bd96e652d42a0f1f0d65e8a5a3b070e63a94fc151dde - SHA-1:
13be370a1a19f9269db8c79ec0bd4c42d3691630 - MD5:
7208e4fe23dee767c3eac7bb5d4f9874 - ssdeep:
1536:uGFseQhtArc7hKlaGIWVE5WsUYl/B15O74tCP1u:XFseAtArc74SgiWa5B1000P0 - TLSH:
T1DD338DF310A7DD4C7ACB9F436EEA2569A095DB486172E764448C272CC47C3BE7E10A50 - Submitted as: 6f3fe19.pdf
- File type: pdf · Size: 51050 bytes
- Verdict: malicious (70/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://gettraff.ru/wb?keyword=find%20the%20orthocenter%20of%20a%20triangle, https://uploads.strikinglycdn.com/files/e331fafc-dfbb-449e-b54d-4cfbd1fe64d7/78535752914.pdf, https://uploads.strikinglycdn.com/files/2808ea58-8eec-4771-8295-817a25f8887a/29160103744.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=find%20the%20orthocenter%20of%20a%20triangle
- https://uploads.strikinglycdn.com/files/e331fafc-dfbb-449e-b54d-4cfbd1fe64d7/78535752914.pdf
- https://uploads.strikinglycdn.com/files/2808ea58-8eec-4771-8295-817a25f8887a/29160103744.pdf
- https://uploads.strikinglycdn.com/files/09139bc0-ff06-459c-82de-dd31c7588feb/58119447659.pdf
- https://uploads.strikinglycdn.com/files/fc16783f-c69a-464b-bf9d-249663f83474/31669514806.pdf
- https://uploads.strikinglycdn.com/files/38134a8c-eec5-4e5f-8698-77cc7e3f2969/kojuxomafuwadij.pdf
- https://cdn.shopify.com/s/files/1/0484/4116/3926/files/47400085330.pdf
- https://cdn.shopify.com/s/files/1/0268/7051/3846/files/catalogue_inax_2020.pdf
- https://cdn.shopify.com/s/files/1/0430/9981/6090/files/rajasthan_patrika_sikar_free_download.pdf
- https://cdn.shopify.com/s/files/1/0266/7718/2646/files/kapavikija.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/7e0fd.pdf
- https://xonuguzuv.weebly.com/uploads/1/3/1/3/131382030/mawuloze.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/delelides_dasexurekiwar_jajumab.pdf
- https://cdn.shopify.com/s/files/1/0430/7727/1713/files/dafunirudoxopewo.pdf
- https://cdn.shopify.com/s/files/1/0436/1938/5502/files/turbo_likes_for_instagram_mod_apk.pdf
- https://cdn.shopify.com/s/files/1/0438/6373/6485/files/mills_eagles_run_4.pdf
- https://cdn.shopify.com/s/files/1/0436/6788/2134/files/classical_and_contemporary_social_theory_investigation_and_application.pdf
- https://cdn.shopify.com/s/files/1/0266/9494/2919/files/third_class_lever_definition.pdf
- https://site-1040170.mozfiles.com/files/1040170/41065912315.pdf
- https://site-1038951.mozfiles.com/files/1038951/65900008794.pdf
- https://site-1038674.mozfiles.com/files/1038674/japowavomuli.pdf
- https://site-1037245.mozfiles.com/files/1037245/xojuxomixuzivoxejip.pdf
- https://site-1042918.mozfiles.com/files/1042918/pudagozukosezu.pdf
- https://site-1040434.mozfiles.com/files/1040434/vetegepubobopol.pdf
- https://site-1039305.mozfiles.com/files/1039305/jexubomubujijake.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- megadezatesaram.weebly.com
- xonuguzuv.weebly.com
- dutitujazekap.weebly.com
- site-1040170.mozfiles.com
- site-1038951.mozfiles.com
- site-1038674.mozfiles.com
- site-1037245.mozfiles.com
- site-1042918.mozfiles.com
- site-1040434.mozfiles.com
- site-1039305.mozfiles.com
- site-1039731.mozfiles.com
- site-1038437.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report