SUSPICIOUS — wexuwojavalak.pdf
SUSPICIOUS — wexuwojavalak.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1a4f1b9d9a3c840333df2b6056babd4629778337f5b7e9d8b3bea41cc73f1543 - SHA-1:
cd65d249ffb21ca0dc2985258420c9f6d03b077e - MD5:
915a767b8c5641a8aa355e6fcd241731 - ssdeep:
1536:yGF4p29XvFf9qBBE1kk8ykmkLbW3UG/FU:rF4pEXvFIBE1kk8ykmkL+PW - TLSH:
T1C6338DF314A7DE4C7B87AB43ADB61529214AC7887232EB90448C766CC17C6BDBF10961 - Submitted as: wexuwojavalak.pdf
- File type: pdf · Size: 51040 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/dc0fdde1-d088-4b41-8b69-ef9564fd106c/febodotafenesoru.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=python%20programming%20zelle%203rd%20edition%20pdf, https://cdn.shopify.com/s/files/1/0427/9736/7452/files/genetic_problems_worksheet_the_wuggy_gumples.pdf, https://cdn.shopify.com/s/files/1/0486/3085/7886/files/2_stage_propane_regulator_with_hose.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=python%20programming%20zelle%203rd%20edition%20pdf
- https://cdn.shopify.com/s/files/1/0427/9736/7452/files/genetic_problems_worksheet_the_wuggy_gumples.pdf
- https://cdn.shopify.com/s/files/1/0486/3085/7886/files/2_stage_propane_regulator_with_hose.pdf
- https://cdn.shopify.com/s/files/1/0496/1760/0675/files/projectile_motion_concepts_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0486/9013/5190/files/death_in_venice.pdf
- https://cdn.shopify.com/s/files/1/0495/1421/7638/files/klammern_auflsen_bungen.pdf
- https://uploads.strikinglycdn.com/files/dc0fdde1-d088-4b41-8b69-ef9564fd106c/febodotafenesoru.pdf
- https://uploads.strikinglycdn.com/files/e4c05484-c5d1-4671-bc3e-172b9b960e41/xofesakonete.pdf
- https://uploads.strikinglycdn.com/files/5f5deee7-5c72-4b34-aed7-11a0093479ae/83430917026.pdf
- https://uploads.strikinglycdn.com/files/62301f4d-98fc-4597-94c8-2c77e457b88c/11175477065.pdf
- https://uploads.strikinglycdn.com/files/62a4201b-c966-483a-a761-8f9553b91350/peguviwukewetaga.pdf
- https://uploads.strikinglycdn.com/files/d6401564-74da-4d8c-b9f0-263dd2471c16/49826044668.pdf
- https://uploads.strikinglycdn.com/files/4aaf9269-5f27-4c01-86e9-77ae2999d4d4/98809568140.pdf
- https://uploads.strikinglycdn.com/files/0bc35787-1eff-4163-b487-ed86bc5187a9/10584058675.pdf
- https://uploads.strikinglycdn.com/files/c1d49846-4854-4ecb-9bd3-dc1e73af2990/timevadogafawetotorug.pdf
- https://uploads.strikinglycdn.com/files/c46a719a-09f4-48b7-ad76-885e5a2b39fa/mazuxonuwalikavol.pdf
- https://uploads.strikinglycdn.com/files/77468cd4-d7cb-4e46-905b-1e570bea9e70/jozoxibumopudari.pdf
- https://uploads.strikinglycdn.com/files/63bec8b8-daed-4f09-ac1e-49540c969578/98004314022.pdf
- https://cdn.shopify.com/s/files/1/0478/7978/2566/files/north_andover_high_school_athletics.pdf
- https://cdn.shopify.com/s/files/1/0485/0162/0898/files/goblin_slayer_read_50.pdf
- https://cdn.shopify.com/s/files/1/0486/0572/4830/files/51744333634.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report