SUSPICIOUS — wikafotu.pdf
SUSPICIOUS — wikafotu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
577e41b58e039ccc386c3311afb9280fcf560c4f6d6997b2d308a5de9767849e - SHA-1:
52d84b6d6d4286188508d8b70dbbae930c6b668a - MD5:
da2d1d179c51053d1027690537504329 - ssdeep:
768:TgGzpDBeqyOdwv0NuaanRgIpd01BuP395f7rLTW85Mo7wFeDEGbtDaDoWpBzYn1I:sGFteJWild0iP39N7rLTW85Mo7w0VbtS - TLSH:
T1B8326CF310A3ED4C7ACB6B439AA71499658AC7887036D7908488772CC97C6FD7F11A60 - Submitted as: wikafotu.pdf
- File type: pdf · Size: 47075 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=lita%20pezo%20final%20fantasy, https://site-1037846.mozfiles.com/files/1037846/jopoxafofe.pdf, https://site-1041075.mozfiles.com/files/1041075/21107966965.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=lita%20pezo%20final%20fantasy
- https://site-1037846.mozfiles.com/files/1037846/jopoxafofe.pdf
- https://site-1041075.mozfiles.com/files/1041075/21107966965.pdf
- https://site-1043705.mozfiles.com/files/1043705/40327638351.pdf
- https://site-1042624.mozfiles.com/files/1042624/burukik.pdf
- https://site-1043051.mozfiles.com/files/1043051/40237378606.pdf
- https://cdn-cms.f-static.net/uploads/4368979/normal_5f87f42e57f72.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f8734fe48583.pdf
- https://cdn-cms.f-static.net/uploads/4367646/normal_5f874b3d48dc8.pdf
- https://cdn-cms.f-static.net/uploads/4369143/normal_5f883d704b5fd.pdf
- https://uploads.strikinglycdn.com/files/ffd88f5d-cbe5-4061-a03c-0b93e110a6c0/kowinewubib.pdf
- https://uploads.strikinglycdn.com/files/c584a6e0-3642-410f-bfb2-d400e1a1f399/befesivekatufatexopuda.pdf
- https://uploads.strikinglycdn.com/files/4900a6a9-9a71-4757-ab8f-55e159a7bb4e/30928917417.pdf
- https://uploads.strikinglycdn.com/files/1e72467b-b988-4cc7-86c9-5d40a65e2fb3/puwavabudixavokozul.pdf
- https://cdn-cms.f-static.net/uploads/4368977/normal_5f8809714a82b.pdf
- https://cdn-cms.f-static.net/uploads/4367268/normal_5f8776516582e.pdf
- https://cdn-cms.f-static.net/uploads/4367922/normal_5f8758c341434.pdf
- https://cdn-cms.f-static.net/uploads/4366961/normal_5f8748eb17f29.pdf
- https://uploads.strikinglycdn.com/files/10d493e8-9e83-465c-80b2-65bca007ab21/13718505691.pdf
- https://uploads.strikinglycdn.com/files/7fc7d127-5067-422a-9b3b-f0e75184d4b1/mufatofazut.pdf
- https://uploads.strikinglycdn.com/files/1cd35119-a49b-4c02-98a5-fa40a2374b87/18399184694.pdf
- https://uploads.strikinglycdn.com/files/3f6d1e6e-a928-4462-956c-f26a484aa81f/32084919248.pdf
- https://uploads.strikinglycdn.com/files/8a77fe5f-da2c-4515-a3ee-2776f65c12e6/16334200682.pdf
- https://uploads.strikinglycdn.com/files/53ddd7e1-1d66-4b1c-b67a-27ff65ef0698/jajabisise.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- site-1037846.mozfiles.com
- site-1041075.mozfiles.com
- site-1043705.mozfiles.com
- site-1042624.mozfiles.com
- site-1043051.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- www.youtube.com
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report