SUSPICIOUS — wonukanugob.pdf
SUSPICIOUS — wonukanugob.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
1590a623c158575539c6b4270590a5bdf01d602e6b18c5c22eeb8719032d13e5 - SHA-1:
ad017cbe9aec90c68187e05bb7a42a9ac7e41503 - MD5:
e7b5f0df77ce7f36824ea73b7dfcb484 - ssdeep:
768:5gGzpDxpaR9/hIxKHwNR8J9cql6I08dYWuBEkAuncPUdnPyq5bbSMP2pAe:6GFFpflR8DaAYWYTj1d6o+o2pAe - TLSH:
T14733AFF318A7DC4C3A8AFF03ADAB1516614AC78C627792510C8C772EE4BC1BDAD20951 - Submitted as: wonukanugob.pdf
- File type: pdf · Size: 50452 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=skyrim%20vr%20blurry, https://uploads.strikinglycdn.com/files/1824cdc6-4628-486e-a4e0-39c756d7b9cb/28349670676.pdf, https://uploads.strikinglycdn.com/files/9c0574dc-e78a-4bf0-88de-fe969d6e06f4/menejujemiruwijusa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=skyrim%20vr%20blurry
- https://uploads.strikinglycdn.com/files/1824cdc6-4628-486e-a4e0-39c756d7b9cb/28349670676.pdf
- https://uploads.strikinglycdn.com/files/9c0574dc-e78a-4bf0-88de-fe969d6e06f4/menejujemiruwijusa.pdf
- https://uploads.strikinglycdn.com/files/28d403b5-15e4-4663-8936-24d3aeed90f5/defozejotobisexuwono.pdf
- https://uploads.strikinglycdn.com/files/7dfae5f2-59f5-464d-ada4-e8a468e8d73b/pisazabiguxeviludelodefu.pdf
- https://uploads.strikinglycdn.com/files/2e43eca4-5de8-4a82-8bc2-b500dedc3a29/12194766295.pdf
- https://uploads.strikinglycdn.com/files/d501b28a-1ae8-4925-b23f-39cb46c99faf/xevewid.pdf
- https://uploads.strikinglycdn.com/files/2fee46ca-aedc-45dc-a4e7-24ebc960b310/72594034197.pdf
- https://uploads.strikinglycdn.com/files/a4d4252a-7689-4b7f-93fc-d915373a5e3b/tekonapuvulakusitanol.pdf
- https://uploads.strikinglycdn.com/files/79aea54a-9704-455b-94e9-dc7581967f94/nimirituxedobewoge.pdf
- https://uploads.strikinglycdn.com/files/2c4b6ac6-b5ae-441f-85db-b2c68e1ca033/17036519751.pdf
- https://uploads.strikinglycdn.com/files/9e2a41c9-8c80-4b81-a36d-d9aab6e39b65/gejovobinizibi.pdf
- https://uploads.strikinglycdn.com/files/70fa2688-2dfd-4f2e-b8f2-5b53e74ca17b/felisufuneraruziseparalow.pdf
- https://uploads.strikinglycdn.com/files/76fdea26-fccc-45ed-bb76-1c0996e8e9c0/borafewasononenim.pdf
- https://cdn.shopify.com/s/files/1/0437/2011/4331/files/19150992858.pdf
- https://cdn.shopify.com/s/files/1/0481/1433/5897/files/magic_chef_mini_fridge_not_cooling.pdf
- https://cdn.shopify.com/s/files/1/0437/6110/7096/files/29320936019.pdf
- https://uploads.strikinglycdn.com/files/54a5b446-6b2c-428e-8f92-c8766131d48d/bawisitoledibotuzu.pdf
- https://uploads.strikinglycdn.com/files/b28677b5-60c7-4181-a093-8f520c24d985/19439786852.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report