SUSPICIOUS — wavegimunijezuwosi.pdf
SUSPICIOUS — wavegimunijezuwosi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
0f2af3dd9a0b29e8dfc07956db32792f16c8da8c1d219ddd58f32268723f6804 - SHA-1:
83f09250e50c9c9f53c316cf9e2226718da3ec9e - MD5:
3b13030145bb9f45a3bcdd591a73d60b - ssdeep:
768:BgGzpDqlBW1WYarrYsiQpEU3oLu1Q1DDXa3o2mbk0L3qZRaOTXY9W5l7IO:yGFelRYgrrIdtcIW5lsO - TLSH:
T1D633BFF340A7EE4C36CBAB4379EA166D218AD6886033AA7055DC776CD4387BD6E40610 - Submitted as: wavegimunijezuwosi.pdf
- File type: pdf · Size: 47990 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=cecotec+power+espresso+20+manual, https://uploads.strikinglycdn.com/files/c8f8a3cb-56e1-4014-bbb8-34614da6977c/polokifogalo.pdf, https://uploads.strikinglycdn.com/files/f05851ee-4775-4a31-b69f-191a58259627/lasalajomiw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=cecotec+power+espresso+20+manual
- https://uploads.strikinglycdn.com/files/c8f8a3cb-56e1-4014-bbb8-34614da6977c/polokifogalo.pdf
- https://uploads.strikinglycdn.com/files/f05851ee-4775-4a31-b69f-191a58259627/lasalajomiw.pdf
- https://uploads.strikinglycdn.com/files/455804a7-7710-4478-914d-2313eccd1149/32924600795.pdf
- https://uploads.strikinglycdn.com/files/9f01d781-1e89-43bf-a4e2-dbe8ca0ac6ce/13174063043.pdf
- https://uploads.strikinglycdn.com/files/a7072569-9dda-4085-b504-8e1836511520/sigilanunufola.pdf
- http://files.grand-beginnings.com/uploads/1/3/1/4/131437464/zuraf.pdf
- http://files.risingearthcreationmyths.com/uploads/1/3/1/8/131856100/2ba436e.pdf
- http://files.99waysesl.com/uploads/1/3/0/7/130776821/65a58.pdf
- https://cdn.shopify.com/s/files/1/0435/2904/4119/files/gukaxol.pdf
- https://cdn.shopify.com/s/files/1/0432/6365/6099/files/lusatogewomo.pdf
- https://cdn.shopify.com/s/files/1/0484/3674/0264/files/tafakisi.pdf
- https://cdn.shopify.com/s/files/1/0432/2718/5311/files/58763307332.pdf
- https://cdn.shopify.com/s/files/1/0428/2325/4179/files/linear_inequalities_in_one_variable_worksheet_doc.pdf
- https://site-1036692.mozfiles.com/files/1036692/27758637252.pdf
- https://site-1037143.mozfiles.com/files/1037143/gofipepobeviz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- files.grand-beginnings.com
- files.risingearthcreationmyths.com
- files.99waysesl.com
- cdn.shopify.com
- site-1036692.mozfiles.com
- site-1037143.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report