SUSPICIOUS — wobakotas.pdf
SUSPICIOUS — wobakotas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
5cfb04fd7be28b262595860504081511858d9d6eb20dc961944d47902208824c - SHA-1:
f5261a869a92534da4bf8278dc02d42771956a47 - MD5:
dcf36d311c0ce5576e153adf1141b8e8 - ssdeep:
768:uugGzpDlnZuHmkSx8HwnBIZpoPUWY3H7yI6eGyyp9JAd:wGFZwdwnBIU63H7yI6eUp9JAd - TLSH:
T1A4319DF3106BDD8C3A83EB436DA725456189C3497237A36014D83B6DC9BCABCAF10960 - Submitted as: wobakotas.pdf
- File type: pdf · Size: 40341 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=tik+tok+indir+apk+android+oyun+club, https://uploads.strikinglycdn.com/files/75b41349-5130-41c2-9a18-5ccb0419ccc4/zezifosewivuwuvedutik.pdf, https://uploads.strikinglycdn.com/files/481f6ef4-2b2a-4ce6-9635-f0b0e74c9cba/85966980559.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=tik+tok+indir+apk+android+oyun+club
- https://uploads.strikinglycdn.com/files/75b41349-5130-41c2-9a18-5ccb0419ccc4/zezifosewivuwuvedutik.pdf
- https://uploads.strikinglycdn.com/files/481f6ef4-2b2a-4ce6-9635-f0b0e74c9cba/85966980559.pdf
- https://uploads.strikinglycdn.com/files/2785ad8b-7a7b-4786-a27b-43b52c4e1cce/kugitexovagubibatubaziza.pdf
- https://uploads.strikinglycdn.com/files/472f5278-b146-4934-a469-77efe770f9bf/mazofipa.pdf
- https://uploads.strikinglycdn.com/files/92bec319-60cf-4918-95dc-b5e599c816f6/fetuxex.pdf
- https://uploads.strikinglycdn.com/files/aec07f98-889c-42f8-b9b0-ae9770421da5/28649313365.pdf
- https://uploads.strikinglycdn.com/files/acff4360-802f-4a5a-8d94-a1e6ceea1192/dovod.pdf
- https://uploads.strikinglycdn.com/files/c8080b46-ff2c-4be7-a59c-482103d06595/35892200731.pdf
- https://uploads.strikinglycdn.com/files/2430c817-3db3-4059-b9e6-70b78791f36d/wigajadimipabopexozusifiz.pdf
- https://uploads.strikinglycdn.com/files/d01e62cb-8083-4f00-af1b-92de20e24641/78450134521.pdf
- https://site-1037175.mozfiles.com/files/1037175/farir.pdf
- https://site-1037859.mozfiles.com/files/1037859/bibexejejinulidodavapu.pdf
- https://site-1039565.mozfiles.com/files/1039565/pelawina.pdf
- https://site-1038439.mozfiles.com/files/1038439/bogomufipifotixik.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1037175.mozfiles.com
- site-1037859.mozfiles.com
- site-1039565.mozfiles.com
- site-1038439.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report