SUSPICIOUS — wofoxipajuvibisanemijela.pdf
SUSPICIOUS — wofoxipajuvibisanemijela.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
28a81707eb1812a93e57645547716e9ba648f758ce8e787e22555a14b042cd13 - SHA-1:
358da4e829463ab0adcb97ce52dfa851e668dca3 - MD5:
26c2ca335d74b94c0cb31f4987a94187 - ssdeep:
768:ngGzpDSNhPhfkB+74+bjxgOW8q7qnuoTRoKtR3LspDyFP:gGFG97rbOOW8juoTJpwuFP - TLSH:
T15D32AEF35017EC8C2AC7AF835EB21099704AE64971766BA405D97B7CC4BC6EC6F41A20 - Submitted as: wofoxipajuvibisanemijela.pdf
- File type: pdf · Size: 47547 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://files.fgslabs.com/uploads/1/3/0/7/130740148/fisir.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=a%25C5%259Fk%25C4%25B1+memnu+pdf+indir, http://files.shopelevateonline.com/uploads/1/3/1/4/131453924/461ac7cdef3dc9.pdf, http://dabadoruw.northlincsbeekeepers.org.uk/uploads/1/3/1/0/131069789/3522838.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=a%25C5%259Fk%25C4%25B1+memnu+pdf+indir
- http://files.shopelevateonline.com/uploads/1/3/1/4/131453924/461ac7cdef3dc9.pdf
- http://dabadoruw.northlincsbeekeepers.org.uk/uploads/1/3/1/0/131069789/3522838.pdf
- http://files.fgslabs.com/uploads/1/3/0/7/130740148/fisir.pdf
- http://sekuw.expansiontheoryproductions.com/uploads/1/3/0/8/130874359/tovupafoko-pitotegekezekuk-dokukexizin.pdf
- https://site-1036775.mozfiles.com/files/1036775/kosagobuzikuxetuman.pdf
- https://site-1036779.mozfiles.com/files/1036779/zawodozivujip.pdf
- https://site-1040262.mozfiles.com/files/1040262/5899562219.pdf
- https://cdn.shopify.com/s/files/1/0481/4779/2021/files/23992537888.pdf
- https://cdn.shopify.com/s/files/1/0482/1572/0093/files/snow_veil_sanctum_claw_id.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- files.shopelevateonline.com
- dabadoruw.northlincsbeekeepers.org.uk
- files.fgslabs.com
- sekuw.expansiontheoryproductions.com
- site-1036775.mozfiles.com
- site-1036779.mozfiles.com
- site-1040262.mozfiles.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report