SUSPICIOUS — 67ca5f5912639.pdf
SUSPICIOUS — 67ca5f5912639.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100), attributed to the Emotet family. 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d0c2b07da6c7fb69f640b86d31d5004cc69d000985779bbe3c59665bcf700b25 - SHA-1:
8eadcff3a63111c249fc3fd541c5379034f242c8 - MD5:
46a2c9c2230b6529c34f8d0232d6be9b - ssdeep:
1536:aGFvpFdEqXXTFMyYGvjgPcs1aWAYKtQU6:DFvpvaXGv6c+a/s - TLSH:
T11534AEF320D7CD8C7A86DB13A8BB1169218BC3487236D790858C6B7DD8BC5AD7E11860 - Submitted as: 67ca5f5912639.pdf
- File type: pdf · Size: 57212 bytes
- Verdict: suspicious (58/100) · Family: Emotet
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: JPCERT/CC: JPCERT_Emotet
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://ggtraff.ru/wb?keyword=elsword%20eternity%20winner%20guide, https://cdn-cms.f-static.net/uploads/4366057/normal_5f877c3a1cc0d.pdf, https://cdn-cms.f-static.net/uploads/4366357/normal_5f87549343229.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=elsword%20eternity%20winner%20guide
- https://cdn-cms.f-static.net/uploads/4366057/normal_5f877c3a1cc0d.pdf
- https://cdn-cms.f-static.net/uploads/4366357/normal_5f87549343229.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f8703bdd32dc.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/fazijopaf.pdf
- https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/batul_funusasaxewa_xiteji_zapareleju.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/domovodibaposix.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/b14c538121.pdf
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/lifevowi-toluwirazebo-tifogad.pdf
- https://uploads.strikinglycdn.com/files/e9ff80d9-f837-416d-b294-c0cbe5a9151d/gimizasuguvutazifala.pdf
- https://uploads.strikinglycdn.com/files/d55aebd5-8b76-4606-9ca9-7a6921d16515/gigelijowu.pdf
- https://uploads.strikinglycdn.com/files/8d630e8c-1804-4f66-a9da-66a05f1c35ed/73299479230.pdf
- https://uploads.strikinglycdn.com/files/f07d2127-aef4-47fb-8a85-24e3e19aaae9/kasefefixodajowawure.pdf
- https://uploads.strikinglycdn.com/files/51e48b68-41dc-4d41-a0fe-818a0b9372d9/mewanose.pdf
- https://uploads.strikinglycdn.com/files/58444a6b-24b3-4b59-aa0f-ec3cfd6f7b15/linowumiwaxolasamup.pdf
- https://uploads.strikinglycdn.com/files/6321211e-cb72-4e76-b339-d046ed8642c7/57521020032.pdf
- https://uploads.strikinglycdn.com/files/c5bce686-5f12-43fe-b389-07b5dd50fb29/zadopotovojefejemaxeg.pdf
- https://uploads.strikinglycdn.com/files/fd076898-de4d-4a7d-8b89-0010b4c08d70/selupupupana.pdf
- https://uploads.strikinglycdn.com/files/ad7aefa2-b460-4bb5-b915-bd9f0dbb28b4/75276680826.pdf
- https://uploads.strikinglycdn.com/files/05a883c1-650e-4e67-9c3e-59501b3f8da6/26538414290.pdf
- https://uploads.strikinglycdn.com/files/d667617c-d893-4cd4-9e6c-3862b882eb23/95379973419.pdf
- https://uploads.strikinglycdn.com/files/8dd95069-c648-4868-8869-f4cdfe39b047/88373829555.pdf
- https://uploads.strikinglycdn.com/files/78934251-fbe8-47c2-a95c-e0d94901a4b5/57846897326.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- babikovinemixe.weebly.com
- kubupukadumu.weebly.com
- guwomenod.weebly.com
- xebikazogede.weebly.com
- sepikupi.weebly.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
More Emotet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report