SUSPICIOUS — ae191.pdf
SUSPICIOUS — ae191.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (68/100), attributed to the Emotet family. 5 of 50 detection engines flagged it.
Identification
- SHA-256:
f33bf8743fee8ab5058c5d4cf6780545d979d2ca004926373cf85881abe598c4 - SHA-1:
be0370ede578cdac007ca392b4fa9975cbaa836d - MD5:
be7caa7c0d8d0edfc712b793be5d73cc - ssdeep:
768:/gGzpDtpoW+eImJb+HMRPsVZBCFUzJBKbuLofhgMby1RBRob8enfrE2i:IGFJpD3FFYWGofhgMbyPHoImfrE2i - TLSH:
T100317DF32097DD8D7A879B03ADBB11AA6149D788A133D7A045CC272CC0BC6BD6F15960 - Submitted as: ae191.pdf
- File type: pdf · Size: 39692 bytes
- Verdict: suspicious (68/100) · Family: Emotet
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 68/100 is the fusion of 5 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://cctraff.ru/wb?keyword=kraken%20pillars%20of%20eternity, https://cdn.shopify.com/s/files/1/0498/4969/6418/files/provas_uva_farias_brito.pdf, https://cdn.shopify.com/s/files/1/0436/6077/1481/files/breville_pie_maker_instruction_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=kraken%20pillars%20of%20eternity
- https://cdn.shopify.com/s/files/1/0497/6050/1921/files/megipijebefatusewapifopu.pdf
- https://cdn.shopify.com/s/files/1/0498/4969/6418/files/provas_uva_farias_brito.pdf
- https://cdn.shopify.com/s/files/1/0436/6077/1481/files/breville_pie_maker_instruction_manual.pdf
- https://uploads.strikinglycdn.com/files/8428d7a9-07d1-4ae8-8c01-d51205588a1f/71857870426.pdf
- https://uploads.strikinglycdn.com/files/1f62624f-75a6-43e8-af25-13be91b8703e/farabupozigapiperif.pdf
- https://uploads.strikinglycdn.com/files/e91e2a14-5ad3-4797-a08b-b8577da805c4/42768407981.pdf
- https://uploads.strikinglycdn.com/files/f1608128-f7a9-483f-b1ee-b19b48b4dced/zemiparabekexilajen.pdf
- https://cdn-cms.f-static.net/uploads/4366984/normal_5f87638946932.pdf
- https://cdn-cms.f-static.net/uploads/4375696/normal_5f89820a8eaca.pdf
- https://cdn-cms.f-static.net/uploads/4368979/normal_5f88930c7a37b.pdf
- https://cdn-cms.f-static.net/uploads/4370055/normal_5f883f3a1a981.pdf
- https://cdn-cms.f-static.net/uploads/4366400/normal_5f8719c9f0e7f.pdf
- https://tegugozitofo.weebly.com/uploads/1/3/0/8/130874592/5078197.pdf
- https://xirofepomare.weebly.com/uploads/1/3/0/8/130814083/gojefofaku-kevijisivo-daxirava-wojopaba.pdf
- https://bigogewoxof.weebly.com/uploads/1/3/0/7/130739615/pudazoretefokafob.pdf
- https://uploads.strikinglycdn.com/files/29cbcffe-954b-4831-b0f3-cfac8720bc29/81591665271.pdf
- https://uploads.strikinglycdn.com/files/0ab8d646-07fd-4cc2-9f66-3a6691dfcf6e/kujawimuzixesepagu.pdf
- https://uploads.strikinglycdn.com/files/83971dd9-249b-4a76-ac6d-dbf7b6acf8bd/bubelepe.pdf
- https://uploads.strikinglycdn.com/files/38c102a7-86c4-423c-a626-f590a20ec495/92290632699.pdf
- https://cdn-cms.f-static.net/uploads/4367951/normal_5f87a24c526d8.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f8915ebb8519.pdf
- https://cdn-cms.f-static.net/uploads/4371023/normal_5f88470dc97db.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- tegugozitofo.weebly.com
- xirofepomare.weebly.com
- bigogewoxof.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
More Emotet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report