SUSPICIOUS — 5eb2e5.pdf
SUSPICIOUS — 5eb2e5.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
56897de0a038090389cde0374b81919e08cf13b9d51e7e9548817efa9986578b - SHA-1:
d07e711f04b07fbea7beb5571a5cc857ecb70e9f - MD5:
709f970f4175e8f23bc009c07c7f7d01 - ssdeep:
768:ntgGzpDYp42uq+WAg2or4Bh5lyhm+vJltzKAlwXZJpbtE:OGFkpfAEzvJaA8/btE - TLSH:
T161306BF71097ED4CBA879B03ADEA2659258AD38C6137A760048C732DD5BC67DBF10860 - Submitted as: 5eb2e5.pdf
- File type: pdf · Size: 38291 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=berserk%20the%20golden%20age%20arc%202%20english%20dub, https://cdn.shopify.com/s/files/1/0479/9168/5273/files/27380646962.pdf, https://cdn.shopify.com/s/files/1/0428/5795/5494/files/84585207110.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=berserk%20the%20golden%20age%20arc%202%20english%20dub
- https://cdn.shopify.com/s/files/1/0479/9168/5273/files/27380646962.pdf
- https://cdn.shopify.com/s/files/1/0428/5795/5494/files/84585207110.pdf
- https://cdn.shopify.com/s/files/1/0502/9707/7925/files/45279520252.pdf
- https://cdn.shopify.com/s/files/1/0437/5651/9585/files/defixiv.pdf
- https://uploads.strikinglycdn.com/files/85a16476-fcd8-4d51-94a5-afe5b3e1fed1/95584210435.pdf
- https://uploads.strikinglycdn.com/files/c45eae3a-d6d0-4c3d-8c62-119b7288c454/68913708399.pdf
- https://uploads.strikinglycdn.com/files/3d9ea9f3-cb95-4fcb-a973-568a1ebe0121/45323985917.pdf
- https://site-1048205.mozfiles.com/files/1048205/xibopemenifomim.pdf
- https://site-1039564.mozfiles.com/files/1039564/peligros_de_las_redes_sociales.pdf
- https://site-1038409.mozfiles.com/files/1038409/nefakoxuximaxajavepul.pdf
- https://site-1043471.mozfiles.com/files/1043471/prelude_to_bruise_saeed_jones.pdf
- https://site-1040574.mozfiles.com/files/1040574/bunubeduzedo.pdf
- https://site-1036633.mozfiles.com/files/1036633/53005896144.pdf
- https://site-1044416.mozfiles.com/files/1044416/laselutuwuvinufarereg.pdf
- https://site-1039608.mozfiles.com/files/1039608/30062233654.pdf
- https://site-1043095.mozfiles.com/files/1043095/68133128146.pdf
- https://zoxaminajoge.weebly.com/uploads/1/3/1/6/131637873/rebakomexusiso_zemagelarew_xituvuf.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/bewoti.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/fubisi.pdf
- https://besavikeneg.weebly.com/uploads/1/3/2/8/132815808/ferageviniwaxov.pdf
- https://uploads.strikinglycdn.com/files/3f43603f-7556-48b3-96f7-40ceffec6e43/ruliv.pdf
- https://uploads.strikinglycdn.com/files/42ed8ea9-4ffb-4349-b00e-0c86c0170700/40306262155.pdf
- https://uploads.strikinglycdn.com/files/208b7e67-6ea7-438b-b4e6-f4bbd144f704/85906867090.pdf
- https://uploads.strikinglycdn.com/files/3aa2d890-7333-4b72-8ee6-7d92ae01e5e6/97456953800.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- site-1048205.mozfiles.com
- site-1039564.mozfiles.com
- site-1038409.mozfiles.com
- site-1043471.mozfiles.com
- site-1040574.mozfiles.com
- site-1036633.mozfiles.com
- site-1044416.mozfiles.com
- site-1039608.mozfiles.com
- site-1043095.mozfiles.com
- zoxaminajoge.weebly.com
- vuxozajuje.weebly.com
- dutitujazekap.weebly.com
- besavikeneg.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- s:\[
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report