SUSPICIOUS — wepezuwodu-fivusosi.pdf
SUSPICIOUS — wepezuwodu-fivusosi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
12d8a38938a77c861b1240347b57598a90b2e0cf5dcd32f55b1ab99ca8a50d7f - SHA-1:
45e1ed36485de1719650ef78a20caa46b862729b - MD5:
94b85ada85c1db5a2f7e7b87f3ff40cd - ssdeep:
1536:MGFXpNsKiMA4BNWqWBeIyRoeiHEsPXIy2xRK5tXdv:pFXpmMXNWqWoIbeFsPXv8RKvN - TLSH:
T17737BFF344A7DE5C7AC79B136CAB115A6189D348617397A0088C6B2C99FC77E7E01C21 - Submitted as: wepezuwodu-fivusosi.pdf
- File type: pdf · Size: 72424 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/824ad13d-d94b-4ae7-ad21-8ce6aabdc0be/mukivevelufet.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=intermediate%20algebra%205th%20edition%20tussy, https://cdn-cms.f-static.net/uploads/4367019/normal_5f872baab61d6.pdf, https://cdn-cms.f-static.net/uploads/4365607/normal_5f871de71b415.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=intermediate%20algebra%205th%20edition%20tussy
- https://cdn-cms.f-static.net/uploads/4367019/normal_5f872baab61d6.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f871de71b415.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f87145311c80.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f870e0fd62fa.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f872164499ec.pdf
- https://site-1042270.mozfiles.com/files/1042270/28552955574.pdf
- https://uploads.strikinglycdn.com/files/824ad13d-d94b-4ae7-ad21-8ce6aabdc0be/mukivevelufet.pdf
- https://uploads.strikinglycdn.com/files/4fa80a1a-4cd9-451a-bad2-da70b79b3f23/27719608124.pdf
- https://uploads.strikinglycdn.com/files/50763e48-dd57-4bd4-8486-ea09e9ee15cc/luwigitameduzuloro.pdf
- https://uploads.strikinglycdn.com/files/c3796f16-b27d-4349-9c96-4263a48ad646/gegebokoninarazufuruwimeb.pdf
- https://uploads.strikinglycdn.com/files/dabe667b-29bf-4d6d-a48b-0fd61d658b0c/2099725668.pdf
- https://rewemekekebaz.weebly.com/uploads/1/3/1/4/131406535/9144969.pdf
- https://vuxozajuje.weebly.com/uploads/1/3/1/3/131379873/rezareludufiven-voxodopi.pdf
- https://walijogopabo.weebly.com/uploads/1/3/0/7/130776167/145769.pdf
- https://tejigenunonim.weebly.com/uploads/1/3/0/8/130813632/xebopuviban.pdf
- https://guwomenod.weebly.com/uploads/1/3/0/8/130873843/3409757.pdf
- https://uploads.strikinglycdn.com/files/c11d9358-fdb6-4e1d-abe9-9dc65c78c6be/64926396553.pdf
- https://uploads.strikinglycdn.com/files/ae556ee1-fc55-427e-95d0-df7b426c6c3a/nubegekunejarijukanime.pdf
- https://uploads.strikinglycdn.com/files/81cb2735-4eb8-4e7e-ab41-f790579ce1ea/52528035824.pdf
- https://uploads.strikinglycdn.com/files/f1e82b17-b9a0-4068-a0b3-218d1c331ef0/4906035895.pdf
- https://uploads.strikinglycdn.com/files/04958325-ddaa-4b63-ac0f-ec329980c655/xufokemelosozafa.pdf
- https://uploads.strikinglycdn.com/files/9e6e6f88-0f57-4e9e-989d-4e6459200325/dopopogejepiso.pdf
- https://uploads.strikinglycdn.com/files/c685c2f5-33d5-4961-8621-4b98657ce6d4/12875319921.pdf
- https://uploads.strikinglycdn.com/files/d558e1b8-17be-4b7e-8e21-8aa81e444754/gevizopezolopegalutani.pdf
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- site-1042270.mozfiles.com
- uploads.strikinglycdn.com
- rewemekekebaz.weebly.com
- vuxozajuje.weebly.com
- walijogopabo.weebly.com
- tejigenunonim.weebly.com
- guwomenod.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report