SUSPICIOUS — 5bc1a93.pdf
SUSPICIOUS — 5bc1a93.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d6183d9d245f79ae75f7dfb26437d4fad5227a09df24c3298cbf1da055f04a49 - SHA-1:
a0e40f4573b5574abec9c44698b4e0eb017e89fa - MD5:
79d29fcc6ad210df0325043e110e6f47 - ssdeep:
768:IgGzpDPpNMZT8OkHPs+FxRxdSQBcZJUEEVsaAqnvt1q+IK2R+ftCb2XrcXmYK7Iu:FGFrpNMpYSQ8GsqnFjd2Rjb2XgWYK7Iu - TLSH:
T1ED328DF344A7EC8DBA8B9B03E9FA10A9619AD3CD5137A79454D8721DC47C2ED7E10820 - Submitted as: 5bc1a93.pdf
- File type: pdf · Size: 44165 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=minn%20kota%20power%20drive%20owners%20manual, https://uploads.strikinglycdn.com/files/0f5759fd-e7f5-47a0-a82b-3adfc6cb626c/75394455632.pdf, https://uploads.strikinglycdn.com/files/cfa2d4a6-1259-4d99-bfa3-cdd2ad72b448/92572836036.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=minn%20kota%20power%20drive%20owners%20manual
- https://uploads.strikinglycdn.com/files/0f5759fd-e7f5-47a0-a82b-3adfc6cb626c/75394455632.pdf
- https://uploads.strikinglycdn.com/files/cfa2d4a6-1259-4d99-bfa3-cdd2ad72b448/92572836036.pdf
- https://uploads.strikinglycdn.com/files/34d419de-6bc4-4bba-ad27-719ddda0a31b/49445377901.pdf
- https://uploads.strikinglycdn.com/files/742e699f-8a7e-44e6-bb4d-dd932540f1e8/49465754607.pdf
- https://uploads.strikinglycdn.com/files/c57784fb-c6a8-48b5-96e8-af8106ea8f22/vikipopoje.pdf
- https://cdn.shopify.com/s/files/1/0437/1211/8952/files/difference_between_food_chain_and_food_web_5_points.pdf
- https://cdn.shopify.com/s/files/1/0499/5937/0904/files/wesabudupevosajaxinog.pdf
- https://cdn.shopify.com/s/files/1/0433/2358/8773/files/jigadefewu.pdf
- https://cdn.shopify.com/s/files/1/0435/5008/1183/files/12809575661.pdf
- https://cdn.shopify.com/s/files/1/0492/3867/1526/files/89123937632.pdf
- https://uploads.strikinglycdn.com/files/f0d762ee-6fa6-4ef4-82a4-07ee97effd99/31776998815.pdf
- https://uploads.strikinglycdn.com/files/833cdfd6-e899-40d4-b5a6-1ebbc6498afd/98539847700.pdf
- https://cdn.shopify.com/s/files/1/0480/3090/8575/files/geometry_angles_quiz.pdf
- https://cdn.shopify.com/s/files/1/0486/2469/7509/files/muvemapominovikijikixevu.pdf
- https://cdn.shopify.com/s/files/1/0435/9002/5375/files/worlds_hardest_game_2_unblocked_cool_math.pdf
- https://jonukejunuxesa.weebly.com/uploads/1/3/1/4/131409236/nebutiven_mowugebemirag_porip.pdf
- https://sujajikozodes.weebly.com/uploads/1/3/1/3/131384638/6933855.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/luvekuvufukukuxup.pdf
- https://site-1042838.mozfiles.com/files/1042838/plural_nouns_with_ies_worksheet.pdf
- https://site-1048449.mozfiles.com/files/1048449/bububepoximamivi.pdf
- https://site-1040125.mozfiles.com/files/1040125/27515876161.pdf
- https://site-1043172.mozfiles.com/files/1043172/jijivonomisajerupa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- jonukejunuxesa.weebly.com
- sujajikozodes.weebly.com
- dapujevubo.weebly.com
- site-1042838.mozfiles.com
- site-1048449.mozfiles.com
- site-1040125.mozfiles.com
- site-1043172.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report