SUSPICIOUS — wufabolejosi.pdf
SUSPICIOUS — wufabolejosi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
5bfb9d7720b828f08ffc3af70dd78ffd289ac5721fe2d384c9d590579fae8e24 - SHA-1:
4321074c4a2da9c12dfb0fa2fc5270e2d2d8d910 - MD5:
770c5645e32d359afd34ecda25473328 - ssdeep:
1536:qGF4ph8I7ZGjQg9/8EQqx7LD7O3PhcxMNgm9tPHxUW7S34n1:TF4phRtGjz/8E/x7f7Opc2NP9xHx63E - TLSH:
T10838CFF31093FD897A8AB743AED61079705E97887121E65105887B6CC8BCAFC6E20F51 - Submitted as: wufabolejosi.pdf
- File type: pdf · Size: 80668 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=tripp%20trapp%20tray%20manual, https://uploads.strikinglycdn.com/files/81b4fd93-369f-4d56-b2e4-81f88a5f6f95/fituxuzani.pdf, https://uploads.strikinglycdn.com/files/68ea2d5f-ea62-499c-9103-bbb42763010d/5266177307.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=tripp%20trapp%20tray%20manual
- https://uploads.strikinglycdn.com/files/81b4fd93-369f-4d56-b2e4-81f88a5f6f95/fituxuzani.pdf
- https://uploads.strikinglycdn.com/files/68ea2d5f-ea62-499c-9103-bbb42763010d/5266177307.pdf
- https://uploads.strikinglycdn.com/files/763553ac-f4d1-4313-8b66-33e531b411ea/mosaf.pdf
- https://uploads.strikinglycdn.com/files/3dd635a3-c946-4ca6-85b3-7d2f3660091c/ugly_duckling_cartoon.pdf
- https://uploads.strikinglycdn.com/files/703f4836-27f0-4d8f-b981-4bce1cada03c/fajut.pdf
- https://uploads.strikinglycdn.com/files/64922fce-dc0b-4651-b812-ef27fb1795b5/gunagozamatavavewuburapi.pdf
- https://uploads.strikinglycdn.com/files/21aaa0f5-6381-4bf3-94dc-773f45fea085/konica_minolta_bizhub_c364_manual.pdf
- https://uploads.strikinglycdn.com/files/bf181984-812a-4245-a3e5-d53fff23b451/75647563853.pdf
- https://uploads.strikinglycdn.com/files/4b6f6eb5-61af-42b5-896d-efa1acdf1585/68607921700.pdf
- https://cdn.shopify.com/s/files/1/0431/0935/1585/files/resurrection_high_school_chicago.pdf
- https://cdn.shopify.com/s/files/1/0435/5247/3252/files/portable_changeable_message_sign_handbook_-_pcms.pdf
- https://cdn.shopify.com/s/files/1/0436/3295/1446/files/rule_of_9s_calculator.pdf
- https://cdn.shopify.com/s/files/1/0496/5321/9479/files/john_deere_lt155_hood_hinge.pdf
- https://cdn.shopify.com/s/files/1/0500/6839/0046/files/prayers_that_rout_demons_by_john_eckhardt_free_download.pdf
- https://wunimebi.weebly.com/uploads/1/3/4/3/134361225/gebifutevinefu_gumag_galide_lepibovasefuk.pdf
- https://xawuwotogot.weebly.com/uploads/1/3/2/6/132695388/8933243.pdf
- https://cdn-cms.f-static.net/uploads/4378164/normal_5f9203f769482.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f89e8ec35c8f.pdf
- https://cdn-cms.f-static.net/uploads/4386354/normal_5f917468b3b70.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- wunimebi.weebly.com
- xawuwotogot.weebly.com
- cdn-cms.f-static.net
- gv.mx
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report