SUSPICIOUS — wopaz.pdf
SUSPICIOUS — wopaz.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e2235325fd3bdefa6fdd9d63e3f37ec1cbc02f546ce263edc1f22607df1ceff8 - SHA-1:
3c0cf49b803eb872b51db891df42bef3e1ca0a26 - MD5:
d734ba2bf231929e14d183217a0e63be - ssdeep:
768:OgGzpDB3KVvhvRpGTBTNN6/bdUC8ZqH3gWGmblDTZe538:rGF1DBTNOyDmg9mblnZe538 - TLSH:
T18632AEF30197ED8C7A8AAF13AA57245D6189C38D6137D36055CD3B2DC0BC2EDAE109A1 - Submitted as: wopaz.pdf
- File type: pdf · Size: 47540 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=el+aire+que+respira+brittainy+c+cherry+pdf, https://uploads.strikinglycdn.com/files/6ce94f11-0438-4378-bdda-aaa76e6ae32d/fulegawugevuvozofa.pdf, https://uploads.strikinglycdn.com/files/c1b15229-df72-48ea-b206-cb0411aba5af/ramelot.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=el+aire+que+respira+brittainy+c+cherry+pdf
- https://uploads.strikinglycdn.com/files/6ce94f11-0438-4378-bdda-aaa76e6ae32d/fulegawugevuvozofa.pdf
- https://uploads.strikinglycdn.com/files/c1b15229-df72-48ea-b206-cb0411aba5af/ramelot.pdf
- https://uploads.strikinglycdn.com/files/6266d936-363a-42f0-8b94-93c4a1a54353/limutokol.pdf
- https://uploads.strikinglycdn.com/files/b971d31d-5242-41fc-afbf-5b98842181aa/116947826.pdf
- https://uploads.strikinglycdn.com/files/037e3120-364a-4cfb-b500-1a5482b1a03b/53951626998.pdf
- https://cdn.shopify.com/s/files/1/0432/8829/7630/files/complex_inheritance_patterns_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0480/7409/6797/files/20371416652.pdf
- https://cdn.shopify.com/s/files/1/0496/5859/3431/files/lowrance_hds_5_gen_2_manual.pdf
- https://cdn.shopify.com/s/files/1/0481/2102/0578/files/harold_and_kumar_tow_truck_driver_actor.pdf
- https://cdn.shopify.com/s/files/1/0469/0558/9920/files/minor_scale_guitar_shapes.pdf
- http://sesixajo.danapayne.net/uploads/1/3/1/6/131607163/a1d5c.pdf
- http://nowuva.fridaytrampoline.com/uploads/1/3/1/8/131856222/8d5f721f95ec6.pdf
- http://nusutov.psfcfiji.org/uploads/1/3/2/6/132696212/7537d720.pdf
- http://files.fortquappellelions.com/uploads/1/3/0/9/130969714/jefofefudixopir.pdf
- http://lolufabo.healthybrowngirl.com/uploads/1/3/0/8/130813855/8a8c5c97.pdf
- http://xuvepek.prairieroseherbals.com/uploads/1/3/1/1/131164573/de0303a89.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- sesixajo.danapayne.net
- nowuva.fridaytrampoline.com
- nusutov.psfcfiji.org
- files.fortquappellelions.com
- lolufabo.healthybrowngirl.com
- xuvepek.prairieroseherbals.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report