SUSPICIOUS — wepoza.pdf
SUSPICIOUS — wepoza.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
d2632692f3c649bf119c52ab5284f4654eaa44fe38566336d7bf952fa48345ab - SHA-1:
e1d46510909553c37a84c175a729fc2acef15f88 - MD5:
ec8d280b0a3f5cfca76e7ef843fe48c7 - ssdeep:
768:tgGzpD4puE15PIblZFZNVJeQsZk/C2rDHNItHo3p5lXcWXbOSv:OGF0puuCxsZk/TNItHip5lscbOSv - TLSH:
T1D2328DF304D7ED4CBA8A9B53ADAB2559018DC7886237E7A04488772CD4BC67D7F109A0 - Submitted as: wepoza.pdf
- File type: pdf · Size: 45661 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=5e%20move%20through%20enemy%20space, https://uploads.strikinglycdn.com/files/2d4dea22-8444-405f-b2be-7520d35d4322/46481756429.pdf, https://uploads.strikinglycdn.com/files/a7913079-8594-4144-95b1-1e3324f6b95f/bukimojodubikosetux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=5e%20move%20through%20enemy%20space
- https://uploads.strikinglycdn.com/files/2d4dea22-8444-405f-b2be-7520d35d4322/46481756429.pdf
- https://uploads.strikinglycdn.com/files/a7913079-8594-4144-95b1-1e3324f6b95f/bukimojodubikosetux.pdf
- https://uploads.strikinglycdn.com/files/5f733a78-9cf2-41a7-acc2-73bfaad674d1/xipidefidamivulafirojafok.pdf
- https://uploads.strikinglycdn.com/files/e915bb4e-175c-4334-a097-116724a2d1fc/kuwubid.pdf
- https://cdn.shopify.com/s/files/1/0498/0342/7993/files/86628982872.pdf
- https://cdn.shopify.com/s/files/1/0476/5148/7910/files/dbx_driverack_pa_manual_greek.pdf
- https://cdn.shopify.com/s/files/1/0440/7784/2597/files/tesozuperusagonip.pdf
- https://cdn.shopify.com/s/files/1/0437/5596/2522/files/dragon_quest_11_jade_skill_guide.pdf
- https://cdn.shopify.com/s/files/1/0480/9811/5737/files/actions_speak_louder_than_words_examples_in_literature.pdf
- https://uploads.strikinglycdn.com/files/5574ac33-8dc4-4c79-814b-824b59948a92/97848132034.pdf
- https://uploads.strikinglycdn.com/files/d6eee614-e8e6-4308-a840-e69cb4a159da/94917499645.pdf
- https://uploads.strikinglycdn.com/files/9d13d2f8-040b-41b0-a2cd-5c4a0f0b2648/zodosine.pdf
- https://uploads.strikinglycdn.com/files/b4b3dcbe-502b-4ec7-944f-435f2c3c56b6/75154958633.pdf
- https://uploads.strikinglycdn.com/files/c7dd6bb5-faef-480d-8bb8-0ef02bd1a0ce/86533746217.pdf
- https://site-1041212.mozfiles.com/files/1041212/pufopizaza.pdf
- https://site-1040124.mozfiles.com/files/1040124/58245343642.pdf
- https://site-1038774.mozfiles.com/files/1038774/reziwagunexudedoranu.pdf
- https://site-1039902.mozfiles.com/files/1039902/puvevinosabut.pdf
- https://uploads.strikinglycdn.com/files/135e5e1c-966d-49f6-8206-0e3616c9f9cf/wenibatebevekajodub.pdf
- https://uploads.strikinglycdn.com/files/81625e3e-b4f3-4f8b-8bfd-813aba2d85c7/35993868193.pdf
- https://uploads.strikinglycdn.com/files/94f401b7-6783-412b-a8ac-bbfb389eab44/fewomu.pdf
- https://uploads.strikinglycdn.com/files/79580b40-3fc7-489d-bb90-bc262c177a79/94554459438.pdf
- https://uploads.strikinglycdn.com/files/3346b5aa-2f06-4f64-9229-77e06cd5bdc0/wusev.pdf
- https://cdn.shopify.com/s/files/1/0428/8829/8659/files/konsep_pembagian_kekuasaan_di_indonesia.pdf
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- site-1041212.mozfiles.com
- site-1040124.mozfiles.com
- site-1038774.mozfiles.com
- site-1039902.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report