SUSPICIOUS — b48d71.pdf
SUSPICIOUS — b48d71.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
efed98ca4d2e958abf28ca65fffebb65ed7d924db803c7f4ebc66cc4a23b51b4 - SHA-1:
25901fd13d01b748534e2b6bb505ad96ff9c010d - MD5:
4a9d63d925fd4242c21033c2ae75d829 - ssdeep:
768:sgGzpDIpQasPKs+zXx+QnE5NuYde6fwqtwJkY1NTXANCpeAO:pGFEpQ62NuYdrE7NTXANCYAO - TLSH:
T1F8329DF350B7DC4CBA8A6B136AEB185D518AD34C613392A449D8372CD4BC6FD7E41A20 - Submitted as: b48d71.pdf
- File type: pdf · Size: 46950 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=mksap%2018%20complete, https://cdn.shopify.com/s/files/1/0435/6059/9711/files/french_gcse_vocab.pdf, https://cdn.shopify.com/s/files/1/0482/4232/7713/files/newton_municipal_school_district.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=mksap%2018%20complete
- https://cdn.shopify.com/s/files/1/0435/6059/9711/files/french_gcse_vocab.pdf
- https://cdn.shopify.com/s/files/1/0482/4232/7713/files/newton_municipal_school_district.pdf
- https://cdn.shopify.com/s/files/1/0429/3220/7782/files/casey_at_the_bat_lesson_activities.pdf
- https://cdn.shopify.com/s/files/1/0501/7642/6144/files/rope_hero_vice_town_hack_version_apk.pdf
- https://uploads.strikinglycdn.com/files/f30ce1b4-0d49-4294-840f-eba352c0eac2/25388528037.pdf
- https://uploads.strikinglycdn.com/files/eef61cf7-e230-4948-9c60-49e9fc44367f/44749457292.pdf
- https://site-1039932.mozfiles.com/files/1039932/wunogidekokubaduzogawag.pdf
- https://site-1040426.mozfiles.com/files/1040426/ginizugadogame.pdf
- https://site-1036681.mozfiles.com/files/1036681/javunigovomovabulajun.pdf
- https://site-1037033.mozfiles.com/files/1037033/goruvatoseloxesisik.pdf
- https://site-1038505.mozfiles.com/files/1038505/47500239792.pdf
- https://uploads.strikinglycdn.com/files/6c93b5e6-a079-46bb-9fd9-2d19460a61e5/wevofitapat.pdf
- https://uploads.strikinglycdn.com/files/c56fbd48-0e1a-423f-8399-63cbd1b4d3d3/90489669417.pdf
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/tufifejus_juwugotelakug_jemibil.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/pegefidokoxim_wobofebiwepulaw.pdf
- https://tajurasexir.weebly.com/uploads/1/3/1/6/131606020/govodijix_jarelu.pdf
- https://loguxofe.weebly.com/uploads/1/3/0/7/130775118/4316678.pdf
- https://site-1037169.mozfiles.com/files/1037169/74784387648.pdf
- https://site-1043043.mozfiles.com/files/1043043/69785462593.pdf
- https://site-1037059.mozfiles.com/files/1037059/96392598142.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1039932.mozfiles.com
- site-1040426.mozfiles.com
- site-1036681.mozfiles.com
- site-1037033.mozfiles.com
- site-1038505.mozfiles.com
- tajurasexir.weebly.com
- loguxofe.weebly.com
- site-1037169.mozfiles.com
- site-1043043.mozfiles.com
- site-1037059.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report