SUSPICIOUS — one_piece_episode_602_english_subbed.pdf
SUSPICIOUS — one_piece_episode_602_english_subbed.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b339a5cd94bfb8e7314b4a7a503e254ee6cd38eec46764987585e491bae437b2 - SHA-1:
3d12ce89d2c000cda3e210368fd3057bc001ac42 - MD5:
14800a527509547436f15a0ea4ee3d22 - ssdeep:
768:9ZgGzpDtpz6FKRMLGJzZdAzWkpYC+Jy/vkVj0L0EgYNZJ00v3FpR0lpR8pR+Qo:4GFpp1dJy/vkVj0LVgMLvaOo - TLSH:
T113307DF3509BDC8C7E8E6F036DA7115AA489D78D6136D6905888372CD0BCAED3F10A61 - Submitted as: one_piece_episode_602_english_subbed.pdf
- File type: pdf · Size: 36889 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=one+piece+episode+602+english+subbed, https://cdn.shopify.com/s/files/1/0432/0120/0288/files/63049873436.pdf, https://cdn.shopify.com/s/files/1/0482/2931/8813/files/72181056910.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=one+piece+episode+602+english+subbed
- https://cdn.shopify.com/s/files/1/0432/0120/0288/files/63049873436.pdf
- https://cdn.shopify.com/s/files/1/0482/2931/8813/files/72181056910.pdf
- https://cdn.shopify.com/s/files/1/0440/7597/4821/files/30667522220.pdf
- https://cdn-cms.f-static.net/uploads/4370555/normal_5f8920b800414.pdf
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f8717ccdb368.pdf
- https://cdn-cms.f-static.net/uploads/4366662/normal_5f87760718c21.pdf
- https://fodezamu.weebly.com/uploads/1/3/1/4/131407453/947c01d8c12.pdf
- https://nijubalalo.weebly.com/uploads/1/3/1/4/131453980/wubopi.pdf
- https://xesaranit.weebly.com/uploads/1/3/2/6/132696194/ravobewojuduk_mugefu_wizudirujitut.pdf
- https://cdn.shopify.com/s/files/1/0462/4479/0426/files/md531ll_a_ipad_model.pdf
- https://cdn.shopify.com/s/files/1/0482/8410/6907/files/android_10_for_oneplus_7_official.pdf
- https://cdn.shopify.com/s/files/1/0481/5775/3497/files/51856729472.pdf
- https://cdn.shopify.com/s/files/1/0496/1851/8179/files/10699663166.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/1040240.pdf
- https://finiluxexolije.weebly.com/uploads/1/3/1/8/131856594/dizibuk_wodokan_jiwale.pdf
- https://kokexofagisukop.weebly.com/uploads/1/3/2/7/132710589/puxiperibari_vawisapusubuwo_luwotib.pdf
- https://uploads.strikinglycdn.com/files/c15ffe71-6ce4-4fdc-b2e2-baf5afb2900f/7562109266.pdf
- https://uploads.strikinglycdn.com/files/e095d2bc-29cf-4ebf-96ca-d9fa3eba1ec8/72999767335.pdf
- https://uploads.strikinglycdn.com/files/57ed9eb6-5686-4563-8901-1d321fcbdae8/bejuluporazulafil.pdf
- https://uploads.strikinglycdn.com/files/7667692d-65e0-4722-a2d4-495a7ca44d87/nolejevajob.pdf
- https://uploads.strikinglycdn.com/files/bf62e3d1-7c97-4cd4-9578-5360ae82caee/mukusanugixobimakidejomon.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- fodezamu.weebly.com
- nijubalalo.weebly.com
- xesaranit.weebly.com
- zafozudakajadev.weebly.com
- finiluxexolije.weebly.com
- kokexofagisukop.weebly.com
- uploads.strikinglycdn.com
- p.nl
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report