SUSPICIOUS — walefubeweten.pdf
SUSPICIOUS — walefubeweten.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
4d8e4c491b4a66c81e893dfb3a603b81189900ca50cc7ffce325e641f2440984 - SHA-1:
cc8bd8f1c32b32a67112b4944efbf796ec7d18f4 - MD5:
2101852402055cbf9ec8c596632fb4c5 - ssdeep:
1536:5GFlfZnZzJtx5xD9eD7FV1FHgRx1vYo5qElRsaIr:MFlfnzJtx5PeNFAH1vrj30r - TLSH:
T19436CFF7149BDD4C3A866B035DE511AE6189C28DB13287B408D8B76D80BC6FD6F04A31 - Submitted as: walefubeweten.pdf
- File type: pdf · Size: 64463 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=example+of+case+study+research+design+pdf, https://uploads.strikinglycdn.com/files/89ff8610-b1b7-4abe-b39a-5496a047db1f/negejagake.pdf, https://uploads.strikinglycdn.com/files/866e0af6-a444-434d-a9f8-0e2f3fe6b142/xinegonugiva.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=example+of+case+study+research+design+pdf
- https://uploads.strikinglycdn.com/files/89ff8610-b1b7-4abe-b39a-5496a047db1f/negejagake.pdf
- https://uploads.strikinglycdn.com/files/866e0af6-a444-434d-a9f8-0e2f3fe6b142/xinegonugiva.pdf
- https://uploads.strikinglycdn.com/files/79d5c4b9-6dcd-4436-b3b1-bbf5a26a43d0/53369950250.pdf
- https://uploads.strikinglycdn.com/files/baab222c-0e27-467b-b35c-af24444dee47/toramumiguvedodika.pdf
- https://uploads.strikinglycdn.com/files/0f09d7cd-4950-404b-96d3-b8864d517946/bikolutikepebaninikolufi.pdf
- https://site-1036760.mozfiles.com/files/1036760/87501831017.pdf
- https://uploads.strikinglycdn.com/files/5f07db50-ea34-4a0a-8b17-82ca74aebf12/96485242518.pdf
- https://uploads.strikinglycdn.com/files/a8fc6881-2dc0-40f8-b77c-85a612820318/newomelifawo.pdf
- https://uploads.strikinglycdn.com/files/a655881c-8c4d-4f43-a6d1-78566d2b3ab2/guzemuweritunopobasogifa.pdf
- https://uploads.strikinglycdn.com/files/bb66ee60-2661-462d-bae6-b0ba47791cad/93368902666.pdf
- https://uploads.strikinglycdn.com/files/63fae33f-5ae0-4470-a80b-6bd107e0b4ff/zizikafopixoziraj.pdf
- http://files.labcharter-pto.com/uploads/1/3/1/3/131379434/4b32ad6.pdf
- http://kupoda.rhombusspace.com/uploads/1/3/1/0/131070147/dutimoritalof_noripojefijote_diterobapozuv.pdf
- http://zewevif.booksandspoons.com/uploads/1/3/2/6/132695471/rupukur.pdf
- http://files.cefcolumbiamidlands.org/uploads/1/3/0/7/130739081/dd581e9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1036760.mozfiles.com
- files.labcharter-pto.com
- kupoda.rhombusspace.com
- zewevif.booksandspoons.com
- files.cefcolumbiamidlands.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report