SUSPICIOUS — wesefer.pdf
SUSPICIOUS — wesefer.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
f0146988ad7bd9260acd7ded36ab1b30342d91c62d9dcd7b95fd06b3b4e47d27 - SHA-1:
7f17731f2ad0a74dfa36c422c49b7d943bbc80a7 - MD5:
1f894504e96ab2324fa24671955093ff - ssdeep:
3072:eF8peZqFcX1w/5teJXbkzNHTuPQmzUuR1NOivZwOyoeYhgrPO/V+KtnbE:ueGqFB/50ZYxHRmzjhUSg7 - TLSH:
T11D3FCFF3109BED8CB7CBDB4328670028B54ADB883263DB94548967ACC5BC67D2D51A60 - Submitted as: wesefer.pdf
- File type: pdf · Size: 158942 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=answer%20to%20the%20universe%20hitchhiker, https://uploads.strikinglycdn.com/files/c07045dd-e81f-4fa4-be65-30a58e8c9e81/71946606599.pdf, https://uploads.strikinglycdn.com/files/7246f770-2c72-4a53-99a4-3bd2894f753c/fexepabezinaliz.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=answer%20to%20the%20universe%20hitchhiker
- https://uploads.strikinglycdn.com/files/c07045dd-e81f-4fa4-be65-30a58e8c9e81/71946606599.pdf
- https://uploads.strikinglycdn.com/files/7246f770-2c72-4a53-99a4-3bd2894f753c/fexepabezinaliz.pdf
- https://uploads.strikinglycdn.com/files/d921af67-7832-4eab-bcee-c16f7af631d1/16379609292.pdf
- https://uploads.strikinglycdn.com/files/f2f44660-523b-4fd9-b875-01ec06031bec/86651259364.pdf
- https://uploads.strikinglycdn.com/files/307beb1d-3cd3-4f87-beb4-54ad67fd373d/zawemutesejubexed.pdf
- https://site-1043765.mozfiles.com/files/1043765/12807249812.pdf
- https://site-1043599.mozfiles.com/files/1043599/11068304140.pdf
- https://site-1040568.mozfiles.com/files/1040568/16039455964.pdf
- https://cdn.shopify.com/s/files/1/0487/9876/1125/files/pwi_homestead_guide.pdf
- https://cdn.shopify.com/s/files/1/0438/9647/1707/files/ivy_league_standings_baseball.pdf
- https://cdn.shopify.com/s/files/1/0435/2815/9396/files/kusiwuxofubod.pdf
- https://cdn.shopify.com/s/files/1/0431/8530/7805/files/xeduge.pdf
- https://cdn.shopify.com/s/files/1/0434/7353/5138/files/flagella_and_cilia_are_made_of_what_cytoskeletal_components.pdf
- https://megadezatesaram.weebly.com/uploads/1/3/0/7/130776649/04609804.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/tifuxasorelav-sunagutigu-gikisifexixabot.pdf
- https://mamunazeve.weebly.com/uploads/1/3/0/8/130814121/3083210.pdf
- https://vuzevarezevarot.weebly.com/uploads/1/3/0/7/130740461/3a6af17.pdf
- https://gusumadanu.weebly.com/uploads/1/3/2/6/132695601/b7841d6.pdf
- https://ligofaxudatejot.weebly.com/uploads/1/3/0/7/130739538/be3f0b1.pdf
- https://jatorogerujew.weebly.com/uploads/1/3/2/7/132710569/a63fb.pdf
- https://bebamewikirebu.weebly.com/uploads/1/3/0/8/130874540/1184125.pdf
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/76c30d49.pdf
- https://cdn-cms.f-static.net/uploads/4365634/normal_5f87409d53ad4.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f88ab955b54e.pdf
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1043765.mozfiles.com
- site-1043599.mozfiles.com
- site-1040568.mozfiles.com
- cdn.shopify.com
- megadezatesaram.weebly.com
- genigudepa.weebly.com
- mamunazeve.weebly.com
- vuzevarezevarot.weebly.com
- gusumadanu.weebly.com
- ligofaxudatejot.weebly.com
- jatorogerujew.weebly.com
- bebamewikirebu.weebly.com
- dutitujazekap.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report