SUSPICIOUS — 5e_monster_manual_download.pdf
SUSPICIOUS — 5e_monster_manual_download.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a757d85d27437c9f04b2a62aa97cb7414a15f2192a1aa86aeffe86f26ae203b8 - SHA-1:
dbec91d8ea270a4d7f51e6d33e85c2184d211745 - MD5:
85c69f9251205ff6d4e9d8e283232b11 - ssdeep:
768:WgGzpDq8PeAiYEo76RLOrmb1otkOPFPDW5fpZv9tNfb:DGF+slkjltRb - TLSH:
T1D3316BF344ABEC4C7A8B9B07EDAB0169118AC78C61379760598C633CD4BC5BE7E10961 - Submitted as: 5e_monster_manual_download.pdf
- File type: pdf · Size: 39456 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=5e+monster+manual+pdf+download, https://uploads.strikinglycdn.com/files/c9b9d325-f246-4423-93d9-0214e2fcb5be/sejarah_bani_umayyah_lengkap.pdf, https://uploads.strikinglycdn.com/files/9b2e7157-cd9c-4f44-ac10-795e1e106bb0/18879375808.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=5e+monster+manual+pdf+download
- https://s3.amazonaws.com/leguvefu/esl_ordinal_numbers_worksheet.pdf
- https://s3.amazonaws.com/jamokaroxoj/76278325637.pdf
- https://s3.amazonaws.com/pazifetanegapu/zibikofimisukobojazukef.pdf
- https://s3.amazonaws.com/zuxadol/python_django_interview_questions_and_answers.pdf
- https://s3.amazonaws.com/tetazino/lawegiluximixov.pdf
- https://uploads.strikinglycdn.com/files/c9b9d325-f246-4423-93d9-0214e2fcb5be/sejarah_bani_umayyah_lengkap.pdf
- https://uploads.strikinglycdn.com/files/9b2e7157-cd9c-4f44-ac10-795e1e106bb0/18879375808.pdf
- https://uploads.strikinglycdn.com/files/208d34c1-2824-4ab5-b3fa-e06b9edb6d59/xirid.pdf
- https://uploads.strikinglycdn.com/files/c421dec5-86c6-4156-915c-51e1637fc1a7/giduvudejesu.pdf
- https://uploads.strikinglycdn.com/files/cf24115b-9028-4988-af21-8f6c69b80bf8/minecraft_korku_maplar_1.7.2.pdf
- https://uploads.strikinglycdn.com/files/69afcc06-5826-43c6-99d6-c53bfa762874/guxopetudema.pdf
- https://uploads.strikinglycdn.com/files/1bf8fcb8-53d6-4147-8e2f-600a2cf2f36a/jadufozubezovepitibe.pdf
- https://s3.amazonaws.com/henghuili-files/best_small_free_editor.pdf
- https://s3.amazonaws.com/saxefi/22862919822.pdf
- https://s3.amazonaws.com/suxiweke/66665560310.pdf
- https://s3.amazonaws.com/gidibesuxi/16372245065.pdf
- https://cdn.shopify.com/s/files/1/0483/4263/0563/files/menschen_im_beruf_pflege_b1_download.pdf
- https://cdn.shopify.com/s/files/1/0499/5540/5992/files/aerb_wireless_keyboard_manual.pdf
- https://cdn.shopify.com/s/files/1/0434/3005/2005/files/vuxigedutobogek.pdf
- https://cdn.shopify.com/s/files/1/0486/6945/8582/files/dnd_5e_spider_staff.pdf
- https://cdn.shopify.com/s/files/1/0502/2393/9753/files/poiseuilles_equation_derivation.pdf
- https://cdn.shopify.com/s/files/1/0463/2811/9457/files/fishman_tonedeq_preamp_eq_manual.pdf
- https://cdn.shopify.com/s/files/1/0483/3211/2035/files/38403384467.pdf
- https://cdn.shopify.com/s/files/1/0494/7194/6919/files/52730290385.pdf
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report