SUSPICIOUS — wetodalobi.pdf
SUSPICIOUS — wetodalobi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
cc7293133877069ac6a6a7027f202a74fef1a1df0fbb85db3f3e822f11fb6c96 - SHA-1:
a46cabd4f7341c682d8570d81004c168f2ad3e1a - MD5:
55d5f92e966935aa02c98f6884fb04d4 - ssdeep:
1536:fGFdQx8fnMeryhCvU1nbfrRfsSAkr6kvL78RB6SnUPA+BC/i5tjr2MT:OFdQx8P7+8ETtfltr2ngVBCK5tr - TLSH:
T1F13CE0F35057EC5CBACB7F576DF6209A644AD388A0B7A6640088BA2CC4BC7FD1E14950 - Submitted as: wetodalobi.pdf
- File type: pdf · Size: 113305 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=human%20migration%20map%20dna, https://cdn-cms.f-static.net/uploads/4385028/normal_5f962fbaed113.pdf, https://uploads.strikinglycdn.com/files/703198f9-60ea-4e3a-a521-c17947a7ffe8/nekopap.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=human%20migration%20map%20dna
- https://cdn-cms.f-static.net/uploads/4385028/normal_5f962fbaed113.pdf
- https://uploads.strikinglycdn.com/files/703198f9-60ea-4e3a-a521-c17947a7ffe8/nekopap.pdf
- https://uploads.strikinglycdn.com/files/8ebb250e-199e-400c-9e30-15e73e6825c4/90007147126.pdf
- https://uploads.strikinglycdn.com/files/43b92c4d-d5fe-4e0f-8dd1-0bbcbbad6f17/guwefavirukes.pdf
- https://cdn-cms.f-static.net/uploads/4375209/normal_5f9dcda3ea64e.pdf
- https://tisefujuset.weebly.com/uploads/1/3/4/4/134488269/25bb5b.pdf
- https://uploads.strikinglycdn.com/files/83f6ee40-4b90-4b45-ac45-05d341d9400d/55532884782.pdf
- https://uploads.strikinglycdn.com/files/4bb7735e-e94b-4cca-8743-379c59c891ac/48226073177.pdf
- https://uploads.strikinglycdn.com/files/c9ed2cbf-fb61-411b-b143-26d8b0588976/62911784363.pdf
- https://uploads.strikinglycdn.com/files/4e8e3de6-5f27-422c-bce3-23812a438b37/82988794258.pdf
- https://uploads.strikinglycdn.com/files/38ad61ac-6b5f-4e0b-89f9-1f278d9153b9/qoo_app_pc.pdf
- https://sasakafu.weebly.com/uploads/1/3/4/3/134371045/8a8cd03db461.pdf
- https://uploads.strikinglycdn.com/files/ad13caf8-53ed-4516-bfdd-0d0a7b22ec40/87034393828.pdf
- https://uploads.strikinglycdn.com/files/32bad402-8b08-44ab-9cbb-eca230563025/86833735145.pdf
- https://uploads.strikinglycdn.com/files/88a9d0b2-60a2-4e6f-9c60-2083f417ae77/nutigikajezajage.pdf
- https://cdn-cms.f-static.net/uploads/4379230/normal_5f99979807da2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- tisefujuset.weebly.com
- sasakafu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report