SUSPICIOUS — ebaf340.pdf
SUSPICIOUS — ebaf340.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
fcb9a41d7d6ab3071b0f14ec7faf9aee69f8e4e8fd74584d75efeed7edd77f91 - SHA-1:
36d9ebf430d7a923d761b08eed84c988442a6803 - MD5:
cd613b80ce27b683510217df36c5f7b4 - ssdeep:
768:fgGzpD8pPmr9zTtiUi+ZqkA5rBB7WKQ6E4hujH81PXGo:oGFIpwi+ZxA5rBAKQr4hbPXGo - TLSH:
T128329FF34053ED4C7A8AAB13ADAB11A541CAD7886137D7B044C8B77DC0BC6ADBE10961 - Submitted as: ebaf340.pdf
- File type: pdf · Size: 45595 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=tuxera%20ntfs%20could%20not%20mount, https://site-1039494.mozfiles.com/files/1039494/pilarimenajivikaligu.pdf, https://site-1042552.mozfiles.com/files/1042552/sapugonex.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=tuxera%20ntfs%20could%20not%20mount
- https://site-1039494.mozfiles.com/files/1039494/pilarimenajivikaligu.pdf
- https://site-1042552.mozfiles.com/files/1042552/sapugonex.pdf
- https://site-1042275.mozfiles.com/files/1042275/3528827442.pdf
- https://site-1048528.mozfiles.com/files/1048528/82567757436.pdf
- https://site-1038880.mozfiles.com/files/1038880/83528490233.pdf
- https://site-1044312.mozfiles.com/files/1044312/xafirezudowodokakap.pdf
- https://site-1039634.mozfiles.com/files/1039634/25567116715.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f871917ce82b.pdf
- https://cdn-cms.f-static.net/uploads/4365560/normal_5f87219399ff3.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f870f8ee7bcb.pdf
- https://cdn-cms.f-static.net/uploads/4365541/normal_5f871e38bc418.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f8724badec59.pdf
- https://uploads.strikinglycdn.com/files/6e66c967-3df8-4c02-ac92-867d2081acca/32899886176.pdf
- https://uploads.strikinglycdn.com/files/1bf1ce31-1d2b-4fda-800b-24057ea910e1/21875374903.pdf
- https://uploads.strikinglycdn.com/files/23795bb9-0e2d-4fa2-b5d6-040a4ec17314/loxadovidezijuzikuvuru.pdf
- https://uploads.strikinglycdn.com/files/f3475d3f-23c8-4276-b81c-1b0d86952880/lidovufunixag.pdf
- https://site-1037082.mozfiles.com/files/1037082/pulode.pdf
- https://site-1039438.mozfiles.com/files/1039438/55000069847.pdf
- https://uploads.strikinglycdn.com/files/872462eb-96ad-4874-a007-8e36dd648cee/60342771613.pdf
- https://uploads.strikinglycdn.com/files/3b9781fc-c00b-40bc-844b-2e9a6293ce84/siregokajixot.pdf
- https://uploads.strikinglycdn.com/files/24e1d017-927f-4c42-ae83-ca60d3e58f52/89128975779.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- site-1039494.mozfiles.com
- site-1042552.mozfiles.com
- site-1042275.mozfiles.com
- site-1048528.mozfiles.com
- site-1038880.mozfiles.com
- site-1044312.mozfiles.com
- site-1039634.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1037082.mozfiles.com
- site-1039438.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report