SUSPICIOUS — 5ae60d21d0223.pdf
SUSPICIOUS — 5ae60d21d0223.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
2a234622ddc18f9d874d83e9e7106226d86dbad5eae02a0580112b10762c8a70 - SHA-1:
2ddab82c21415b499ce6e686f346a130e6b73429 - MD5:
4f7a13fccc6d049f9317beecab9ae85a - ssdeep:
768:wgGzpDuqqCkOGBHmNtlf/Uy40BYxAUXqzvCDAK0KSqlB19WE:dGFSE1UytKHHDAvKS89WE - TLSH:
T114328EF350A7DD8C7A8B5F17AD6B1559948ED788A027D790008CB62CC4BCAFE6F00915 - Submitted as: 5ae60d21d0223.pdf
- File type: pdf · Size: 46163 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=sonic%20saber%20manual, https://cdn-cms.f-static.net/uploads/4368763/normal_5f8a422929104.pdf, https://cdn-cms.f-static.net/uploads/4369190/normal_5f879af273f24.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=sonic%20saber%20manual
- https://cdn-cms.f-static.net/uploads/4368763/normal_5f8a422929104.pdf
- https://cdn-cms.f-static.net/uploads/4369190/normal_5f879af273f24.pdf
- https://cdn-cms.f-static.net/uploads/4366327/normal_5f901e34cc52c.pdf
- https://cdn-cms.f-static.net/uploads/4368985/normal_5f87daddda2f4.pdf
- https://cdn-cms.f-static.net/uploads/4368226/normal_5f876b7b036ee.pdf
- https://cdn-cms.f-static.net/uploads/4381531/normal_5f8b20f48d2dc.pdf
- https://cdn-cms.f-static.net/uploads/4366045/normal_5f8c121c75885.pdf
- https://cdn-cms.f-static.net/uploads/4371553/normal_5f93fd5e8526d.pdf
- https://cdn-cms.f-static.net/uploads/4366993/normal_5f874494c7809.pdf
- https://vilemanunopabom.weebly.com/uploads/1/3/4/3/134317174/zisopukerobon-vizobadajedada.pdf
- https://jupisururixed.weebly.com/uploads/1/3/4/3/134339091/xafavexefisekel_sibanujofif_fawukizuxovutu.pdf
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/goxarujemexogu_mosegozivi_fofuwad_kezobal.pdf
- https://xesaranit.weebly.com/uploads/1/3/2/6/132696194/4091873.pdf
- https://uploads.strikinglycdn.com/files/b7a1c60b-7768-4895-8f8d-e128a672350a/18633313937.pdf
- https://uploads.strikinglycdn.com/files/81fab1fe-40cf-4af4-b8ae-5cf776f24101/92154282130.pdf
- https://uploads.strikinglycdn.com/files/03501ea9-e1ab-4b95-8299-ba84c66c9b77/ketobup.pdf
- https://uploads.strikinglycdn.com/files/a5f88d1b-0264-447f-b8c7-94fd1026ec6b/7022367821.pdf
- https://uploads.strikinglycdn.com/files/1b4198b1-1ba6-470f-8fe0-48435f306b00/3131244676.pdf
- https://fupesovuzej.weebly.com/uploads/1/3/4/0/134016868/leguwokenesom.pdf
- https://fupexorugukemig.weebly.com/uploads/1/3/0/8/130814763/fomotonidifalu.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/nukunuraki.pdf
- https://pubetisor.weebly.com/uploads/1/3/4/3/134348812/disuzizawewi.pdf
- https://vonubaxuted.weebly.com/uploads/1/3/1/4/131452839/fazifobisas_rapibipe.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/ac58ca23.pdf
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- vilemanunopabom.weebly.com
- jupisururixed.weebly.com
- wepugimi.weebly.com
- xesaranit.weebly.com
- uploads.strikinglycdn.com
- fupesovuzej.weebly.com
- fupexorugukemig.weebly.com
- guwomenod.weebly.com
- pubetisor.weebly.com
- vonubaxuted.weebly.com
- dejolezeg.weebly.com
- xedaliwim.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report