SUSPICIOUS — woxefopexafu.pdf
SUSPICIOUS — woxefopexafu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
a1f1b272e6ef021a8c6797e51895271c953e423217f028010c7d81b25586c098 - SHA-1:
61600cdfce754d08705d9697636816fc932383c4 - MD5:
f0006ba82fd7a22973f4a67e2a59f668 - ssdeep:
1536:3GFU5MUFSIhRIGsDMMhuiPDaew8UuDB//ZVdbzNHN:WFU5vSYRsDnDLwRo/hVdPNt - TLSH:
T11435CFF3D067FCC9679EBB136EAA2059614AC64470329A5114C93B7CC4B83FCBE21991 - Submitted as: woxefopexafu.pdf
- File type: pdf · Size: 59686 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=lg%20model%20lp0814wnr%20manual, https://cdn.shopify.com/s/files/1/0498/4494/5051/files/extremerate_replacement_guide_for_nintendo_switch_shell.pdf, https://cdn-cms.f-static.net/uploads/4376629/normal_5f8a8a761ae10.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=lg%20model%20lp0814wnr%20manual
- https://cdn.shopify.com/s/files/1/0498/4494/5051/files/extremerate_replacement_guide_for_nintendo_switch_shell.pdf
- https://cdn-cms.f-static.net/uploads/4376629/normal_5f8a8a761ae10.pdf
- https://gitexerepasali.weebly.com/uploads/1/3/4/5/134577484/7521463.pdf
- https://cdn.shopify.com/s/files/1/0486/6939/3046/files/bidirijotumojavu.pdf
- https://cdn.shopify.com/s/files/1/0496/6445/8908/files/watch_the_joker_2019.pdf
- https://cdn.shopify.com/s/files/1/0507/4639/2751/files/zobomofokuguvodaxujilef.pdf
- https://uploads.strikinglycdn.com/files/ab4a8e3c-b083-4948-ade1-d717dd95c3fc/73093876636.pdf
- https://duxuborokepab.weebly.com/uploads/1/3/4/4/134449965/jelosi.pdf
- https://cdn.shopify.com/s/files/1/0440/7744/9366/files/candy_mountain_charlie_quotes.pdf
- https://cdn.shopify.com/s/files/1/0432/0896/6306/files/metallurgy_notes_for_iit-jee.pdf
- https://cdn-cms.f-static.net/uploads/4367019/normal_5f9105f6e337b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- gitexerepasali.weebly.com
- uploads.strikinglycdn.com
- duxuborokepab.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report