MALICIOUS — wozowire.pdf
MALICIOUS — wozowire.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
a935e1c393336fc51a6f947c7cd0760c00593d23ca34f3515686194d987848ff - SHA-1:
6901f552090fbc2b7d18e6d0f9ccb483afae8880 - MD5:
7ca4a51b036e6ea46a306fb53ca1237d - ssdeep:
1536:FO2C4h/qXQb8eoO7/eDo8KAQHDeu+WlD3I1IY/mmSGpAJxCeSWLeAbzYfPMX:02b8lO72DoUjBWlbI18mDpJeReLg - TLSH:
T10239D0F3619BCD8CB98B9F436EF61459718DC2886520D6A450C4BB6CCC6C27E6E20F11 - Submitted as: wozowire.pdf
- File type: pdf · Size: 87055 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!7CA4A51B036E
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://jottigo.ru/wb?keyword=cat%20talking%20buttons%20tiktok, https://cdn-cms.f-static.net/uploads/4420441/normal_5fe809a52f047.pdf, https://cdn-cms.f-static.net/uploads/4387424/normal_6015fc6a64fed.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jottigo.ru/wb?keyword=cat%20talking%20buttons%20tiktok
- https://cdn-cms.f-static.net/uploads/4420441/normal_5fe809a52f047.pdf
- https://cdn-cms.f-static.net/uploads/4387424/normal_6015fc6a64fed.pdf
- https://wudigunufite.weebly.com/uploads/1/3/4/6/134611509/2219558.pdf
- https://cdn-cms.f-static.net/uploads/4456379/normal_5fd274e49d04a.pdf
- https://static.s123-cdn-static.com/uploads/4474998/normal_5ff7697ebd34b.pdf
- http://shtangye.xyz/turefinujositohokl.pdf
- http://kpupnov.pro/lesson_plan_ideas_for_sunday_school3w8zj.pdf
- http://grantmedica.ru/tiktok_liker_followers_apprpsbo.pdf
- https://taxufutusa.weebly.com/uploads/1/3/4/5/134514166/385602b81.pdf
- https://static.s123-cdn-static.com/uploads/4484156/normal_5fd02caa936e0.pdf
- https://cdn-cms.f-static.net/uploads/4490918/normal_60114ad86dc92.pdf
- http://itravelgr.com/jivinolefelosepegph1z.pdf
- http://about-central.com/50200817788pxzg2.pdf
- https://static.s123-cdn-static.com/uploads/4414515/normal_5fff2de73a4e6.pdf
- http://kudretbozaci.com/devalapiromizirifnj3k6.pdf
- http://jadebey-x.com/rockstar_games_launcher_errordudny.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- jottigo.ru
- cdn-cms.f-static.net
- wudigunufite.weebly.com
- static.s123-cdn-static.com
- shtangye.xyz
- kpupnov.pro
- grantmedica.ru
- taxufutusa.weebly.com
- itravelgr.com
- about-central.com
- kudretbozaci.com
- jadebey-x.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report