SUSPICIOUS — wexavibugowajajazimev.pdf
SUSPICIOUS — wexavibugowajajazimev.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7a871f5fb729d7f03f79a9a755ad4e1e1443768cfbce6f9fd777507235eaf76b - SHA-1:
49b8852d41a5804928414fb53442d70ef90d1493 - MD5:
d1845491594097c5632d9a1efaaf879d - ssdeep:
768:/gGzpD+Q8vv74cqcVJY6Vf5DIZwvlv4D6/ZTXH827VWWkEoXCKPyZNE:IGFKD7CQfo0lQD6/ZTXv7VWWRoy4iE - TLSH:
T13533AFF3515BCC8C7BC6AB0369BA0418A047C78D7172AAB095997B6CC4BC6FC6E40E51 - Submitted as: wexavibugowajajazimev.pdf
- File type: pdf · Size: 51952 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/b07a2d0e-4a98-4b08-9c4a-283bb682eca5/zagemo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=descargar+one+piece+mega, https://uploads.strikinglycdn.com/files/b07a2d0e-4a98-4b08-9c4a-283bb682eca5/zagemo.pdf, https://uploads.strikinglycdn.com/files/0c29c59f-0cba-45cf-8957-c0ae7fcc42b6/xivebapomik.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=descargar+one+piece+mega
- https://uploads.strikinglycdn.com/files/b07a2d0e-4a98-4b08-9c4a-283bb682eca5/zagemo.pdf
- https://uploads.strikinglycdn.com/files/0c29c59f-0cba-45cf-8957-c0ae7fcc42b6/xivebapomik.pdf
- https://uploads.strikinglycdn.com/files/e1a0b18d-7cf9-40fa-870b-a44807bbcc84/lesagarujajapariso.pdf
- https://site-1039578.mozfiles.com/files/1039578/vejigejosikeni.pdf
- https://site-1036883.mozfiles.com/files/1036883/seridomabutudufilazeki.pdf
- https://site-1039669.mozfiles.com/files/1039669/84493295805.pdf
- https://site-1040383.mozfiles.com/files/1040383/mapibe.pdf
- https://site-1036830.mozfiles.com/files/1036830/visojomogazazepol.pdf
- https://site-1037010.mozfiles.com/files/1037010/5844229858.pdf
- https://site-1036944.mozfiles.com/files/1036944/begeloxemapoma.pdf
- https://uploads.strikinglycdn.com/files/61be8da8-a705-4807-a858-f3acfc6a4f5a/60091551955.pdf
- https://uploads.strikinglycdn.com/files/5e7109f8-b34d-4907-af52-30940d6230c7/sexoxajizogufes.pdf
- https://uploads.strikinglycdn.com/files/0d1a0319-39ae-492d-80eb-2666b4be8b67/nifodemekopof.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1039578.mozfiles.com
- site-1036883.mozfiles.com
- site-1039669.mozfiles.com
- site-1040383.mozfiles.com
- site-1036830.mozfiles.com
- site-1037010.mozfiles.com
- site-1036944.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report