SUSPICIOUS — 6118e9a.pdf
SUSPICIOUS — 6118e9a.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e08f7b8f06bbaba8cd0bacaa562a42de515b134ca559f7a8891b278a20dc361e - SHA-1:
7637ee138f85748d30167d1e753ebcbd9678000a - MD5:
3485724c2740f22e54a7b2b5ef11bdde - ssdeep:
768:ZgGzpDGpfIZA3RdlMRTGdPNjER3zEGm7eqGcvZ5zsiE8VkxPKKObyb06WxhRPIdR:aGFCpHvl8GdhERgUPKKOo0/xwdJz - TLSH:
T138349EF310A7EE5CBE879B03AEFA2559A489D7495073A760448C7B2DC07C6BE7E00950 - Submitted as: 6118e9a.pdf
- File type: pdf · Size: 53121 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=friday%20rules%20pdf, https://cdn.shopify.com/s/files/1/0502/1673/0799/files/hero_line_wars_starlight_build_guide.pdf, https://cdn.shopify.com/s/files/1/0502/4265/0277/files/fireboy_and_watergirl_unblocked_at_school_66.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=friday%20rules%20pdf
- https://cdn.shopify.com/s/files/1/0502/1673/0799/files/hero_line_wars_starlight_build_guide.pdf
- https://cdn.shopify.com/s/files/1/0502/4265/0277/files/fireboy_and_watergirl_unblocked_at_school_66.pdf
- https://cdn.shopify.com/s/files/1/0498/2980/6242/files/nuwazilixodokepi.pdf
- https://cdn.shopify.com/s/files/1/0500/7301/0364/files/learning_clock_time_worksheets.pdf
- https://cdn-cms.f-static.net/uploads/4388613/normal_5f8f8e6bb7357.pdf
- https://cdn-cms.f-static.net/uploads/4387412/normal_5f8ce35bbc708.pdf
- https://cdn-cms.f-static.net/uploads/4372360/normal_5f8a533e9206c.pdf
- https://cdn-cms.f-static.net/uploads/4366343/normal_5f92132825a04.pdf
- https://cdn-cms.f-static.net/uploads/4375070/normal_5f89710980b20.pdf
- https://uploads.strikinglycdn.com/files/16d88c01-14de-4768-aa0f-58b6660ba3d5/wawaxufaligatuv.pdf
- https://uploads.strikinglycdn.com/files/0f8e4f66-12ef-4c42-a6cb-63bf24a426fb/giwovexunilufiwaxe.pdf
- https://uploads.strikinglycdn.com/files/038e25e4-a478-4254-9ae9-b99bd7ce6ae6/gedosokepanikifiwu.pdf
- https://uploads.strikinglycdn.com/files/f8825ffa-4ada-4b9b-b41b-1e2487b7e16d/ussr_ymca_parody.pdf
- https://uploads.strikinglycdn.com/files/4e7db274-bb66-4864-8477-f4b7bfbd9c4b/22042048825.pdf
- https://uploads.strikinglycdn.com/files/bdd28d69-92da-4ae3-bffa-d3723e45233f/clases_de_equitacion.pdf
- https://uploads.strikinglycdn.com/files/3e7ff306-dd61-4757-a0b2-c3a57484b441/59104995610.pdf
- https://uploads.strikinglycdn.com/files/13d2602f-4b27-4e40-84bd-77ff81f3d9ae/board_kings_hack_apk_2019.pdf
- https://uploads.strikinglycdn.com/files/526dbcef-e073-4138-b43c-265d6a9c4687/puwubajobomivilawevele.pdf
- https://uploads.strikinglycdn.com/files/9672df87-a741-4688-bd84-e6240bf70ec5/44525143444.pdf
- https://uploads.strikinglycdn.com/files/0c0ef243-01e7-4616-a293-829ee40cc1e5/davokipopizib.pdf
- https://uploads.strikinglycdn.com/files/1e5bdef3-5bfe-4816-9b7b-4e9cdc0fd992/solenumokedodugig.pdf
- https://uploads.strikinglycdn.com/files/46cfabae-24b9-4b4e-862e-16727c2d41a7/92095185945.pdf
- https://s3.amazonaws.com/jikopot/inspiration_contemporary_design_methods_in_architecture.pdf
- https://s3.amazonaws.com/felasorarabipis/81899764827.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report