SUSPICIOUS — ae6247e.pdf
SUSPICIOUS — ae6247e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b18cdb1d6e2a6212df1c32c16d2650529e8448e79200f5d11f9814c952fb5c5f - SHA-1:
9c4262e57f594d6527b77250f5d4e613be2843da - MD5:
47bab088937359dc7e586604ca0f0ab1 - ssdeep:
768:2gGzpDqpCdpiXbnaNQEf/6/CR4T4cARTsvaAggyvPCLTXopNnbMjp7BbYbwM2:jGFmpmpcbl6Sman2bwabwM2 - TLSH:
T18335B0F350A3EE8CBA4B6B53EDB610586448E38D5132A76054C87A7CD4BC5FD6E01B09 - Submitted as: ae6247e.pdf
- File type: pdf · Size: 58218 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=123%20movie%20app, https://site-1040096.mozfiles.com/files/1040096/desagelalodapodig.pdf, https://site-1037268.mozfiles.com/files/1037268/31807627597.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=123%20movie%20app
- https://site-1040096.mozfiles.com/files/1040096/desagelalodapodig.pdf
- https://site-1037268.mozfiles.com/files/1037268/31807627597.pdf
- https://site-1048574.mozfiles.com/files/1048574/76898059419.pdf
- https://site-1038627.mozfiles.com/files/1038627/5243824894.pdf
- https://cdn.shopify.com/s/files/1/0434/7029/1096/files/24698908723.pdf
- https://cdn.shopify.com/s/files/1/0481/2600/1315/files/my_hero_academia_movie_watch_online_reddit.pdf
- https://cdn.shopify.com/s/files/1/0430/7222/5442/files/simpsons_tapped_out_event_list.pdf
- https://cdn.shopify.com/s/files/1/0430/9712/9109/files/tbc_feral_tank_gear_guide.pdf
- https://site-1038608.mozfiles.com/files/1038608/42729345447.pdf
- https://site-1040683.mozfiles.com/files/1040683/58392927239.pdf
- https://cdn-cms.f-static.net/uploads/4365540/normal_5f876ae4696a8.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f870d053f6eb.pdf
- https://site-1036746.mozfiles.com/files/1036746/gibogametebovetilef.pdf
- https://site-1048222.mozfiles.com/files/1048222/tikanabi.pdf
- https://site-1037035.mozfiles.com/files/1037035/lawulikuligoka.pdf
- https://cdn-cms.f-static.net/uploads/4367635/normal_5f87683549f39.pdf
- https://cdn-cms.f-static.net/uploads/4366311/normal_5f8780193cbac.pdf
- https://cdn-cms.f-static.net/uploads/4365627/normal_5f8736660c092.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1040096.mozfiles.com
- site-1037268.mozfiles.com
- site-1048574.mozfiles.com
- site-1038627.mozfiles.com
- cdn.shopify.com
- site-1038608.mozfiles.com
- site-1040683.mozfiles.com
- cdn-cms.f-static.net
- site-1036746.mozfiles.com
- site-1048222.mozfiles.com
- site-1037035.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report