SUSPICIOUS — wobubakoza.pdf
SUSPICIOUS — wobubakoza.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5d2f9e5a4944ec2d670100a6a98f21c9f4195aacd819587a17e5db4877368207 - SHA-1:
86846985c3c9731e2650b35a0a7fe50c8efbf570 - MD5:
baca6574395119d309e4f52cb3d56d50 - ssdeep:
768:FgGzpD6UdOQngG14OS0pfDD+GG/h0xSw4szytOQ:WGFuUdnflG/hVszytOQ - TLSH:
T1472F8DF72497EC897AC3DB07AEE7105D2049C38C2132A2A091987B2DD1786FDBE40875 - Submitted as: wobubakoza.pdf
- File type: pdf · Size: 34940 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/85b2e3d9-7427-4db7-a7b9-b17fd59caba8/kekofaxigusexajakinekub.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=kumbida+pona+deivam+video+song+free+download, https://uploads.strikinglycdn.com/files/85b2e3d9-7427-4db7-a7b9-b17fd59caba8/kekofaxigusexajakinekub.pdf, https://uploads.strikinglycdn.com/files/be402fe4-beda-4f60-b169-1eccc445295d/tipojovekafivepuga.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=kumbida+pona+deivam+video+song+free+download
- https://uploads.strikinglycdn.com/files/85b2e3d9-7427-4db7-a7b9-b17fd59caba8/kekofaxigusexajakinekub.pdf
- https://uploads.strikinglycdn.com/files/be402fe4-beda-4f60-b169-1eccc445295d/tipojovekafivepuga.pdf
- https://uploads.strikinglycdn.com/files/d6c50381-70c1-4a99-8816-1463186b7b22/35470096178.pdf
- https://cdn.shopify.com/s/files/1/0486/7483/2534/files/the_relative_location_of_ethiopia_changed_when.pdf
- https://cdn.shopify.com/s/files/1/0436/2282/6142/files/53658244836.pdf
- https://cdn.shopify.com/s/files/1/0434/4234/0007/files/anatomy_and_physiology_coloring_workbook_answers_chapter_3.pdf
- https://cdn.shopify.com/s/files/1/0492/3464/1052/files/refonufowopowurevivu.pdf
- https://cdn.shopify.com/s/files/1/0499/8361/9232/files/mafabuzek.pdf
- https://cdn.shopify.com/s/files/1/0480/6233/3092/files/symbol_of_usv-jsc.pdf
- https://cdn.shopify.com/s/files/1/0435/5447/2087/files/rijapubojeg.pdf
- http://files.pilates-journey.com/uploads/1/3/0/7/130775554/pipekirosusa_zexesor.pdf
- http://files.wishingwellcharity.org/uploads/1/3/1/4/131437242/7355579.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- files.pilates-journey.com
- files.wishingwellcharity.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report