SUSPICIOUS — wapojeditowudakeror.pdf
SUSPICIOUS — wapojeditowudakeror.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3e6be9c1454148cf43e652b5a41e84a4bd44a2d075a2c900ec01701eadf628e7 - SHA-1:
27b5eb72ec6a50e64635b20eb07df55fca7b0a69 - MD5:
7d79b68680ff65d1321dd8fd73aac730 - ssdeep:
768:UgGzpDqppwCOi0yZyW5aoNmORWwL1POEVhXZbvBWnWXeFo4BipQGkE:hGFmpKC8nWRh3ZbvBWnWAoTpQGkE - TLSH:
T12A339DF36067EE4C7E8B6B07AEA71599758AD2892021D7A084CC376CD4BC7ED3E00651 - Submitted as: wapojeditowudakeror.pdf
- File type: pdf · Size: 49592 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/4eefdb2c-9229-4b58-900a-6bd0b7a4a959/nexanixotub.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=xcom%202%20quick%20save, https://site-1040096.mozfiles.com/files/1040096/45085046463.pdf, https://site-1043453.mozfiles.com/files/1043453/91313886967.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=xcom%202%20quick%20save
- https://site-1040096.mozfiles.com/files/1040096/45085046463.pdf
- https://site-1043453.mozfiles.com/files/1043453/91313886967.pdf
- https://site-1038451.mozfiles.com/files/1038451/mipewufiwe.pdf
- https://site-1044185.mozfiles.com/files/1044185/59287174537.pdf
- https://takijotirodone.weebly.com/uploads/1/3/1/6/131637658/sukoxajapemofu.pdf
- https://lanasasaf.weebly.com/uploads/1/3/0/8/130815311/zetenorabadolaf.pdf
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/ddc22363a5ae.pdf
- https://cdn.shopify.com/s/files/1/0493/4647/8239/files/oakland_coliseum_layout.pdf
- https://cdn.shopify.com/s/files/1/0437/6304/0408/files/76646474594.pdf
- https://cdn.shopify.com/s/files/1/0434/0298/5621/files/64677839761.pdf
- https://cdn-cms.f-static.net/uploads/4366959/normal_5f872f0a941f1.pdf
- https://cdn-cms.f-static.net/uploads/4366317/normal_5f88d5ef6df8f.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f86fa16347a3.pdf
- https://uploads.strikinglycdn.com/files/4eefdb2c-9229-4b58-900a-6bd0b7a4a959/nexanixotub.pdf
- https://uploads.strikinglycdn.com/files/4f6fc1f2-c77a-4244-95bd-c85b1501dbed/zazipezusuwumeki.pdf
- https://uploads.strikinglycdn.com/files/27b50dec-fe73-47b9-a7ae-465fc3aa827b/92998719100.pdf
- https://uploads.strikinglycdn.com/files/00ee9038-5c8e-499b-9a1b-78c22ff79a67/lanubisezuvoxej.pdf
- https://site-1043650.mozfiles.com/files/1043650/37445243948.pdf
- https://site-1036880.mozfiles.com/files/1036880/85903304720.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- site-1040096.mozfiles.com
- site-1043453.mozfiles.com
- site-1038451.mozfiles.com
- site-1044185.mozfiles.com
- takijotirodone.weebly.com
- lanasasaf.weebly.com
- viweposedijul.weebly.com
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1043650.mozfiles.com
- site-1036880.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report