SUSPICIOUS — wigonowijavokegirig.pdf
SUSPICIOUS — wigonowijavokegirig.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
283720b355d8d7f0bf3bed0e60d2dc41cbf34d13d65941cd5c51ddb4e8a9e3da - SHA-1:
e7db7bb025f13a036ed067373f52b580260a55a6 - MD5:
9c4db1134698560552407e3fdf13802c - ssdeep:
768:wgGzpDML/cxu/mpwvdcQ4yryx7FhgFHSu9T6TdEs6P29i8:dGFIvvdc/yU7LgFyuB6TdyP29i8 - TLSH:
T198318CF3105BED8CBA87A7439DBB0565628AD3886233976005CC772DC4BC6AD6F20961 - Submitted as: wigonowijavokegirig.pdf
- File type: pdf · Size: 41066 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=vowel%20digraphs%20worksheets%201st%20grade, https://uploads.strikinglycdn.com/files/a62fd7c2-a29d-4afc-a020-7a38949c5086/94821519783.pdf, https://uploads.strikinglycdn.com/files/128adb48-ed90-4a7c-9138-ac8ba5afea88/74348251011.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=vowel%20digraphs%20worksheets%201st%20grade
- https://uploads.strikinglycdn.com/files/a62fd7c2-a29d-4afc-a020-7a38949c5086/94821519783.pdf
- https://uploads.strikinglycdn.com/files/128adb48-ed90-4a7c-9138-ac8ba5afea88/74348251011.pdf
- https://uploads.strikinglycdn.com/files/1c8316e1-04e5-4208-9e11-67c7837fa8f0/jaxoluxibi.pdf
- https://uploads.strikinglycdn.com/files/b77e8a58-a247-44c4-87be-6755d9768173/80071853917.pdf
- https://uploads.strikinglycdn.com/files/3f57e37e-bb5a-440b-aa6c-638e9255a681/31840237335.pdf
- https://cdn-cms.f-static.net/uploads/4388814/normal_5f90d11829581.pdf
- https://cdn-cms.f-static.net/uploads/4369183/normal_5f88f30abdbcf.pdf
- https://s3.amazonaws.com/datarofapakil/79298065225.pdf
- https://s3.amazonaws.com/memul/95666324696.pdf
- https://s3.amazonaws.com/fukezavazuj/lijoguwojapikilota.pdf
- https://s3.amazonaws.com/zunaduxa/5685484777.pdf
- https://s3.amazonaws.com/zirojopemup/63903981509.pdf
- https://jixepelisu.weebly.com/uploads/1/3/2/6/132695865/6138923.pdf
- https://xapinetevum.weebly.com/uploads/1/3/4/3/134330578/zomesutor.pdf
- https://cdn.shopify.com/s/files/1/0484/7524/2657/files/zukokikulilakazolasenaf.pdf
- https://cdn.shopify.com/s/files/1/0483/0275/1905/files/little_live_pets_bird_instructions.pdf
- https://uploads.strikinglycdn.com/files/bb1a8eee-0d92-4789-8d15-e71a81fa3b31/ledajevunetubilelefa.pdf
- https://uploads.strikinglycdn.com/files/f82670db-d7e7-4827-86cb-cf740cd8d1a4/nelelakuwamojamuves.pdf
- https://uploads.strikinglycdn.com/files/3b233e92-6089-472b-a0f3-68d6e2fbf64f/ns_toor_balance_sheet_analysis.pdf
- https://uploads.strikinglycdn.com/files/03acebdb-7f2a-4ba5-8d1d-b447e83aca79/64581697111.pdf
- https://uploads.strikinglycdn.com/files/69e0e268-a00b-480a-9e5f-c1bc0e2a8b0a/83525771987.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- jixepelisu.weebly.com
- xapinetevum.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report