SUSPICIOUS — woxew.pdf
SUSPICIOUS — woxew.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
ee3eeac7ca7c0d541c562a996bdc8fd28efc7e7f37a0aa0a64cab64252df36b3 - SHA-1:
34b10b6c158cb1995b22e897c89ac8db733707f4 - MD5:
b424626313214033bd9ea4ffe2de1689 - ssdeep:
768:OgGzpDlpMkkdTK8xRHwU3349UsfMKcYyumvb6hkQovEjOAJmJmRDdznLcAzNAU8y:rGF5pMndTK84s+iv4OAYJmRDdFAU8y - TLSH:
T1C1338CF351A7EE4C3A879B136DEF295D5188D78C6132ABA00998772DD0BC27D3E10921 - Submitted as: woxew.pdf
- File type: pdf · Size: 52158 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=adiabatic+lapse+rate+aviation, https://cdn.shopify.com/s/files/1/0501/6862/7384/files/exprimidor_de_jugo_naranja_manual.pdf, https://cdn.shopify.com/s/files/1/0500/4568/1824/files/cinetica_de_particulas_ejercicios_resueltos.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=adiabatic+lapse+rate+aviation
- https://cdn.shopify.com/s/files/1/0433/7808/1959/files/dotageruva.pdf
- https://cdn.shopify.com/s/files/1/0501/6862/7384/files/exprimidor_de_jugo_naranja_manual.pdf
- https://cdn.shopify.com/s/files/1/0500/4568/1824/files/cinetica_de_particulas_ejercicios_resueltos.pdf
- https://cdn.shopify.com/s/files/1/0268/7926/2918/files/craftsman_snowblower_manual_88173.pdf
- https://uploads.strikinglycdn.com/files/e5985481-324d-4ac5-b6be-7b41e3ebdcb6/lilotividoketojaxutu.pdf
- https://uploads.strikinglycdn.com/files/6e539820-e527-41f2-b6c7-736fe782ea48/1712844058.pdf
- https://uploads.strikinglycdn.com/files/e80b5998-8497-4908-98fc-40d963a56032/13572162095.pdf
- https://s3.amazonaws.com/magapeguwabe/86827428716.pdf
- https://s3.amazonaws.com/gupuso/83709935846.pdf
- https://s3.amazonaws.com/rizezobabub/vozifezuvasizolubeketor.pdf
- https://s3.amazonaws.com/fekazudabo/fitut.pdf
- https://s3.amazonaws.com/mesotodimus/pitonolasabijaranodi.pdf
- https://cdn.shopify.com/s/files/1/0438/4784/4000/files/arabian_nights_in_bengali.pdf
- https://cdn.shopify.com/s/files/1/0431/9107/4976/files/manual_burr_grinder_canada.pdf
- https://cdn.shopify.com/s/files/1/0500/4460/0470/files/what_does_full_send_mean_nelk.pdf
- https://cdn.shopify.com/s/files/1/0499/2735/6577/files/meaning_of_napkin_in_american_english.pdf
- https://uploads.strikinglycdn.com/files/f3add05d-3743-419a-bff4-538d431f3acc/steppenwolf_hermann_hesse.pdf
- https://uploads.strikinglycdn.com/files/a8861f90-c7aa-446c-a6bb-bd62994bff83/dutavo.pdf
- https://uploads.strikinglycdn.com/files/a9096dac-d261-44f1-b7f2-f30e57883645/87414896590.pdf
- https://uploads.strikinglycdn.com/files/54812fce-2895-4fc6-a6f0-e2c3efdea00b/muni_3_kanchana_2_mp3_songs_download.pdf
- https://uploads.strikinglycdn.com/files/04127619-65a8-4706-904b-5f37c1033e6a/tuluke.pdf
- https://uploads.strikinglycdn.com/files/c0124365-b6d6-4b14-abe8-f3c6ff3e6bf3/sarejivavanep.pdf
- https://uploads.strikinglycdn.com/files/e564c673-4832-4caa-a980-b29b753bfc52/kusemulolilelolomidukapo.pdf
- https://uploads.strikinglycdn.com/files/c3e8e078-82f6-487f-8abc-780cc86604e8/damomazugebowok.pdf
Embedded domains
- gettraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report