SUSPICIOUS — 50ea6.pdf
SUSPICIOUS — 50ea6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
b92434fdb166fdc8f2590228ce9373958c8a7bda7df3032608d80e7b790f77ca - SHA-1:
a86016c561ecd934be31757f83b2ef547fb18a00 - MD5:
4c2c576b111b2cfc640a7e4c0d6aee12 - ssdeep:
1536:oGFvTpz4sy03iu4mafPN1V5vA1jDEerBadhdLYjSwbkQBIJpf:FFvTp0+fSPTV541zNadhdLYjSS6j - TLSH:
T19A39DFF35057EC9C698EAB83B89A121C715AD7CC6232975015CC2B7CC6F86BE2F00991 - Submitted as: 50ea6.pdf
- File type: pdf · Size: 89918 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=sanyo%20nimh%20battery%20charger%20manual, https://cdn.shopify.com/s/files/1/0496/5875/7277/files/mirureroxel.pdf, https://cdn.shopify.com/s/files/1/0432/5474/3200/files/garedosap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=sanyo%20nimh%20battery%20charger%20manual
- https://cdn.shopify.com/s/files/1/0496/5875/7277/files/mirureroxel.pdf
- https://cdn.shopify.com/s/files/1/0432/5474/3200/files/garedosap.pdf
- https://cdn.shopify.com/s/files/1/0484/8546/6267/files/linajovulenufikidikoziri.pdf
- https://cdn.shopify.com/s/files/1/0478/9783/7734/files/nvidia_quadro_k2200_benchmark.pdf
- https://cdn.shopify.com/s/files/1/0436/4114/3454/files/urbanears_plattan_bluetooth_manual.pdf
- https://cdn.shopify.com/s/files/1/0492/6826/1020/files/gmo_salmon_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0432/2813/5592/files/26946131965.pdf
- https://cdn.shopify.com/s/files/1/0497/8488/1301/files/52474526770.pdf
- https://site-1039153.mozfiles.com/files/1039153/927419860.pdf
- https://site-1039840.mozfiles.com/files/1039840/4178542922.pdf
- https://cdn.shopify.com/s/files/1/0482/9393/7316/files/whirlpool_stove_f2.pdf
- https://cdn.shopify.com/s/files/1/0437/7001/9994/files/chemistry_density_problems_worksheet_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0432/2358/0830/files/softball_mom_shirts_amazon.pdf
- https://uploads.strikinglycdn.com/files/be0349e2-0e37-4f2d-8676-6e504693f82d/kabusunusojuguv.pdf
- https://uploads.strikinglycdn.com/files/3c35db9d-978d-40e3-8d25-975506244b22/zipolaxavasesozanifigivi.pdf
- https://uploads.strikinglycdn.com/files/b771ab68-6ee7-4206-92d6-09fb2f25feff/nuxesubasabuwulewolov.pdf
- https://uploads.strikinglycdn.com/files/a2e8f589-855f-4eaa-952b-c1dcc0473ef2/29298374206.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- site-1039153.mozfiles.com
- site-1039840.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report