SUSPICIOUS — wewaropawanad.pdf
SUSPICIOUS — wewaropawanad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3187565db19dcd229cef682b8ee4cd672c81f8960f882651ee881af1ceaf9bf8 - SHA-1:
103116aadd99531c00704d1e919a286d21c55de4 - MD5:
bfa89f8e8af592e5926a52cc62a8293c - ssdeep:
768:DgGzpDCp67/JyEFhjdOv3fVEmR44+2T52qVG/QYL7ozflThEFffcAFVk:8GFmp0+EmRz+4ZVGL6flThEFncA/k - TLSH:
T135318CF310A7EC4C7A8B9B479EEB119A9189C348107BE790099C773DD47C6EDAE20950 - Submitted as: wewaropawanad.pdf
- File type: pdf · Size: 43210 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/f63e606f-ef07-43f8-be6e-1698478f2adf/xikewojudinotamunapis.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=kenmore%2010%20sewing%20machine%20manual, https://uploads.strikinglycdn.com/files/f63e606f-ef07-43f8-be6e-1698478f2adf/xikewojudinotamunapis.pdf, https://uploads.strikinglycdn.com/files/b93e15de-e2c6-449d-9550-6fe71c9140ca/sotimifitavos.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=kenmore%2010%20sewing%20machine%20manual
- https://uploads.strikinglycdn.com/files/f63e606f-ef07-43f8-be6e-1698478f2adf/xikewojudinotamunapis.pdf
- https://uploads.strikinglycdn.com/files/b93e15de-e2c6-449d-9550-6fe71c9140ca/sotimifitavos.pdf
- https://uploads.strikinglycdn.com/files/bf257b0e-39c2-4f1d-b879-39736e6dcbd2/fusesaniv.pdf
- https://uploads.strikinglycdn.com/files/215b4cda-9f80-4d35-b938-1ae3c5a52a7d/wikika.pdf
- https://cdn-cms.f-static.net/uploads/4366036/normal_5f86f9fd64eee.pdf
- https://cdn-cms.f-static.net/uploads/4367019/normal_5f8730ffa488e.pdf
- https://cdn.shopify.com/s/files/1/0266/8167/1872/files/shoe_pattern_making_book.pdf
- https://cdn.shopify.com/s/files/1/0496/4833/7049/files/dual_xdma760_manual.pdf
- https://cdn.shopify.com/s/files/1/0484/4784/8602/files/pokemon_season_4_episode_16.pdf
- https://cdn.shopify.com/s/files/1/0497/9297/5011/files/91448775737.pdf
- https://cdn.shopify.com/s/files/1/0432/5398/9534/files/bafivuluwiwesusulorukosi.pdf
- https://site-1039633.mozfiles.com/files/1039633/82465183737.pdf
- https://site-1039863.mozfiles.com/files/1039863/63370359261.pdf
- https://site-1043047.mozfiles.com/files/1043047/44955902903.pdf
- https://uploads.strikinglycdn.com/files/80aca7ed-607b-4a5a-8bf7-44fdc5ffa468/7366511329.pdf
- https://uploads.strikinglycdn.com/files/01688059-22f4-416d-b159-322ea1d971cf/103011971.pdf
- https://uploads.strikinglycdn.com/files/adb00171-f4c1-41e2-af54-2c3ffbbef797/16732067726.pdf
- https://uploads.strikinglycdn.com/files/bdecc389-c1f0-45aa-9678-b5d347d1fa22/29875584730.pdf
- https://uploads.strikinglycdn.com/files/d1909306-5cb8-43a7-a2fc-ef62f8d12fad/43339897641.pdf
- https://cdn.shopify.com/s/files/1/0485/9985/9360/files/m_card_app_for_android.pdf
- https://cdn.shopify.com/s/files/1/0439/4529/6027/files/misibokulaveguti.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- site-1039633.mozfiles.com
- site-1039863.mozfiles.com
- site-1043047.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report