SUSPICIOUS — wefukiref.pdf
SUSPICIOUS — wefukiref.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
2f46e32bc228da9535cd55b075f2ecd2bab19191dfdaf3c2420ed1df840bcd8d - SHA-1:
894ebfaa973e748a38a59b3769b2b5906d93c6fe - MD5:
355d8de59c1394d41e182937dcc32b8e - ssdeep:
768:PgGzpDHpd+9didGAyTFnicoDZfXmQK6aOpurr1W/GIgx+Sm9CgpMC0Q:4GFzpdJ9XmgaOp2W/GIsm9CwMC0Q - TLSH:
T108317DF340E3EC8C7A4B6B07ADAB0159518ED74D113AA761558C772EC07C6EE3E80961 - Submitted as: wefukiref.pdf
- File type: pdf · Size: 41721 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=gta%20san%20andreas%20hayalet%20araba%20modu%20indir, https://uploads.strikinglycdn.com/files/9a24ad6e-76e4-4dc4-9e8b-395316b39229/venajixojixoxawinomiro.pdf, https://uploads.strikinglycdn.com/files/fa575c2e-306f-49d5-bfbb-46effdd1d85b/pedefeda.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=gta%20san%20andreas%20hayalet%20araba%20modu%20indir
- https://uploads.strikinglycdn.com/files/9a24ad6e-76e4-4dc4-9e8b-395316b39229/venajixojixoxawinomiro.pdf
- https://uploads.strikinglycdn.com/files/fa575c2e-306f-49d5-bfbb-46effdd1d85b/pedefeda.pdf
- https://uploads.strikinglycdn.com/files/92b07f91-dd32-4f65-a332-a8ecc161936d/93983164499.pdf
- https://uploads.strikinglycdn.com/files/9f301687-ad0f-4205-9544-7038d2e37fb8/rulomosase.pdf
- https://uploads.strikinglycdn.com/files/cfa4bacd-46e9-4e8d-be41-750159a664e2/88539261952.pdf
- https://uploads.strikinglycdn.com/files/5a06bf8a-ffd4-4ffb-bfd6-6b8170f870da/fuwegefevibafodutod.pdf
- https://uploads.strikinglycdn.com/files/35e0a6a4-4ed4-44b9-8493-c67aa2182570/nulusij.pdf
- https://uploads.strikinglycdn.com/files/397516f8-b81e-4291-a55a-9272a105f4e7/wofenidemimofamudav.pdf
- https://uploads.strikinglycdn.com/files/5b3cbf87-80c3-4e40-a907-91cf199591fc/22690672614.pdf
- https://uploads.strikinglycdn.com/files/cec89f8a-bb70-483d-b857-6d60db450ac5/woliseloxevibezivus.pdf
- https://uploads.strikinglycdn.com/files/b1a75c3b-0e6e-4183-994e-d77f5301a090/31324298018.pdf
- https://uploads.strikinglycdn.com/files/53c2c5e4-b239-428a-9080-752debffbc9e/21541055319.pdf
- https://cdn-cms.f-static.net/uploads/4369936/normal_5f88ec2e7f36e.pdf
- https://cdn-cms.f-static.net/uploads/4370056/normal_5f880df5b2e22.pdf
- https://cdn-cms.f-static.net/uploads/4370309/normal_5f882e0a9e8ba.pdf
- https://cdn-cms.f-static.net/uploads/4367642/normal_5f891eb07abe5.pdf
- https://cdn-cms.f-static.net/uploads/4366976/normal_5f88d730d50ab.pdf
- https://cdn-cms.f-static.net/uploads/4367940/normal_5f8909cb72257.pdf
- https://cdn-cms.f-static.net/uploads/4365562/normal_5f8739bdd3604.pdf
- https://cdn.shopify.com/s/files/1/0497/3491/0101/files/kopuwudujoripezatug.pdf
- https://cdn.shopify.com/s/files/1/0484/3814/9274/files/1419871406.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report