SUSPICIOUS — wozoxawe.pdf
SUSPICIOUS — wozoxawe.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1cd68eb84b5a6ed19bad36cbd8a277d1b8a402f5ba71bcc1ef8c010f59a2e02e - SHA-1:
4c07818027c15cf5490f29abbb7beb95f894ac34 - MD5:
aa58b7363dea7faa57418d2bb80b8763 - ssdeep:
1536:yGFMp+9+QvrhElAGQAvGi/r51hX3f9sCwW:rFMp+UIhEvX1pP9ss - TLSH:
T1EE34AEF311E7ED8CB68B6F036DE71158A49AE7885026E7A0148C376DD5BC6BC3E10A11 - Submitted as: wozoxawe.pdf
- File type: pdf · Size: 54187 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/a5e1de61-535c-4dfe-ba94-3d56f470742e/32072305067.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=head%20shoulders%20knees%20and%20toes%20song, https://uploads.strikinglycdn.com/files/18ea6134-b9e5-4dfc-9b8e-27f004b783f3/tezamojugenemod.pdf, https://uploads.strikinglycdn.com/files/2210e15d-7e40-4fc8-8605-cad215ededd5/71149681486.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=head%20shoulders%20knees%20and%20toes%20song
- https://uploads.strikinglycdn.com/files/18ea6134-b9e5-4dfc-9b8e-27f004b783f3/tezamojugenemod.pdf
- https://uploads.strikinglycdn.com/files/2210e15d-7e40-4fc8-8605-cad215ededd5/71149681486.pdf
- https://uploads.strikinglycdn.com/files/a92b4223-6a30-403c-b08d-c0017f266263/somifudozamebanemuzigase.pdf
- https://uploads.strikinglycdn.com/files/d53b2c55-c669-4a66-912a-4cbc6e4e6a0f/33159195342.pdf
- https://uploads.strikinglycdn.com/files/a5e1de61-535c-4dfe-ba94-3d56f470742e/32072305067.pdf
- https://uploads.strikinglycdn.com/files/92f3f21f-6502-4b69-bd40-5a5781975002/34040603788.pdf
- https://uploads.strikinglycdn.com/files/a88a1fa0-313e-4dc8-89b0-7a08878e8b74/50829456203.pdf
- https://uploads.strikinglycdn.com/files/9f6dee6a-e497-41ba-86b7-076e1e1c2565/tasadabonu.pdf
- https://site-1036630.mozfiles.com/files/1036630/jajorozokebudezoliguvesej.pdf
- https://site-1037916.mozfiles.com/files/1037916/bupilewonivipin.pdf
- https://site-1036898.mozfiles.com/files/1036898/nixekes.pdf
- https://site-1042496.mozfiles.com/files/1042496/fepazubexosinulapafa.pdf
- https://uploads.strikinglycdn.com/files/4a1c102f-bb23-4707-8a39-8abc7120062c/togogivovudibimad.pdf
- https://uploads.strikinglycdn.com/files/43308269-9689-41f1-a58d-141b4011b085/97305870036.pdf
- https://uploads.strikinglycdn.com/files/74d9226c-b51e-4498-98e7-5d5c981a80cf/fepumopaxotamixavugoz.pdf
- https://site-1043651.mozfiles.com/files/1043651/1015137829.pdf
- https://site-1038961.mozfiles.com/files/1038961/30720538358.pdf
- https://site-1042658.mozfiles.com/files/1042658/vokusoke.pdf
- https://site-1039797.mozfiles.com/files/1039797/polijujevevodakuka.pdf
- https://site-1044473.mozfiles.com/files/1044473/jalotikodege.pdf
- https://site-1038820.mozfiles.com/files/1038820/wabenodijiv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- site-1036630.mozfiles.com
- site-1037916.mozfiles.com
- site-1036898.mozfiles.com
- site-1042496.mozfiles.com
- site-1043651.mozfiles.com
- site-1038961.mozfiles.com
- site-1042658.mozfiles.com
- site-1039797.mozfiles.com
- site-1044473.mozfiles.com
- site-1038820.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report