SUSPICIOUS — wopawode.pdf
SUSPICIOUS — wopawode.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
e1492607f621b925fa4241426d2ce3b7b8b7e7bed8e5e90b3d511a23b83adaeb - SHA-1:
eb68980e19d173e6d4a78d0599f8b4b96c4c36e2 - MD5:
0ba3fcf661ed2baec325733faf37ac3a - ssdeep:
768:NgGzpDwpmUCJRDzJFs9NSVZbvAY8UBrqoNuUpvmtgKF5:uGF0p0frAMrquugcgKF5 - TLSH:
T163305DF305A7ED4C7A879B87ACBB2599548AC78D62239780458C6B6CC4BC67DBF00520 - Submitted as: wopawode.pdf
- File type: pdf · Size: 36875 bytes
- Verdict: suspicious (35/100)
Detections (2 of 50 engines)
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=lanzetti%20bolsas%20con%20vis%C3%B3n, https://site-1038503.mozfiles.com/files/1038503/jidilo.pdf, https://site-1048205.mozfiles.com/files/1048205/ravew.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=lanzetti%20bolsas%20con%20vis%C3%B3n
- https://site-1038503.mozfiles.com/files/1038503/jidilo.pdf
- https://site-1048205.mozfiles.com/files/1048205/ravew.pdf
- https://site-1040376.mozfiles.com/files/1040376/88376924298.pdf
- https://site-1043292.mozfiles.com/files/1043292/42832954742.pdf
- https://site-1041761.mozfiles.com/files/1041761/wuderakosivi.pdf
- https://cdn-cms.f-static.net/uploads/4366646/normal_5f87883585db6.pdf
- https://cdn-cms.f-static.net/uploads/4367960/normal_5f87873c5ab9e.pdf
- https://cdn-cms.f-static.net/uploads/4365626/normal_5f87810704aaf.pdf
- https://cdn-cms.f-static.net/uploads/4367643/normal_5f878419d89d2.pdf
- https://cdn-cms.f-static.net/uploads/4367941/normal_5f878a351b33f.pdf
- https://uploads.strikinglycdn.com/files/e3b8e90c-8642-4b89-ba40-6fa9d7e6f289/nokesewimilaruf.pdf
- https://uploads.strikinglycdn.com/files/e17e23bd-5f4c-446e-aadf-2e709c458d8d/98720620363.pdf
- https://uploads.strikinglycdn.com/files/c0efc187-e874-4f50-8bed-4fbd14304945/xasesola.pdf
- https://cdn-cms.f-static.net/uploads/4367296/normal_5f873d84efc42.pdf
- https://cdn-cms.f-static.net/uploads/4366630/normal_5f878b7c8a7dc.pdf
- https://cdn-cms.f-static.net/uploads/4366993/normal_5f8739e82e79c.pdf
- https://cdn-cms.f-static.net/uploads/4368225/normal_5f876a8d695a5.pdf
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/910391.pdf
- https://ninukiwipovesot.weebly.com/uploads/1/3/0/9/130969879/bdbc33bd.pdf
- https://site-1044186.mozfiles.com/files/1044186/15703383112.pdf
- https://site-1043582.mozfiles.com/files/1043582/15393401628.pdf
- https://site-1043963.mozfiles.com/files/1043963/mifesomemezazazo.pdf
- https://site-1040003.mozfiles.com/files/1040003/jutesi.pdf
- https://site-1039830.mozfiles.com/files/1039830/kurosin.pdf
Embedded domains
- cctraff.ru
- site-1038503.mozfiles.com
- site-1048205.mozfiles.com
- site-1040376.mozfiles.com
- site-1043292.mozfiles.com
- site-1041761.mozfiles.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- vekejuritikoj.weebly.com
- ninukiwipovesot.weebly.com
- site-1044186.mozfiles.com
- site-1043582.mozfiles.com
- site-1043963.mozfiles.com
- site-1040003.mozfiles.com
- site-1039830.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report