SUSPICIOUS — wavavomewa.pdf
SUSPICIOUS — wavavomewa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
369b7622e3f6ed2dfb50e99a02c715cd571ae62be7b35ef46595a942cf128162 - SHA-1:
1597b6bf990a547b2a1a2183fcfdd526c4dd25c0 - MD5:
723471631ea3d92ceb0e1b3a835e357b - ssdeep:
1536:xGFReSoIVCksT+gP1/mFe/piCsjEN2X4eT63etH0q:UFReSx3sxVm+iCsjWC4Q63+ - TLSH:
T12F36AFF36167EC4D7ACB9B17ADB31069704ADB89313292A044CD772CC5BCABC6D01A51 - Submitted as: wavavomewa.pdf
- File type: pdf · Size: 65045 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=asus%20ux305%20specs, https://cdn.shopify.com/s/files/1/0497/3897/3345/files/79911320882.pdf, https://cdn.shopify.com/s/files/1/0487/9227/3061/files/english_speaking_course_in.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=asus%20ux305%20specs
- https://cdn.shopify.com/s/files/1/0497/3897/3345/files/79911320882.pdf
- https://cdn.shopify.com/s/files/1/0487/9227/3061/files/english_speaking_course_in.pdf
- https://cdn.shopify.com/s/files/1/0486/0808/4128/files/9886365882.pdf
- https://cdn.shopify.com/s/files/1/0433/3237/0584/files/x_rates_currency_calculator.pdf
- https://cdn.shopify.com/s/files/1/0481/7800/4135/files/principal_agent_theory_in_public_administration.pdf
- https://firedisivimi.weebly.com/uploads/1/3/0/9/130969818/lopuma-japokogunowa-pizejoset.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/78259c9fc3.pdf
- https://cdn-cms.f-static.net/uploads/4365607/normal_5f8b101133703.pdf
- https://cdn-cms.f-static.net/uploads/4365584/normal_5f8727c1283ec.pdf
- https://cdn-cms.f-static.net/uploads/4382617/normal_5f8cfc641e8fd.pdf
- https://cdn-cms.f-static.net/uploads/4380694/normal_5f8bb7bb743c0.pdf
- https://cdn-cms.f-static.net/uploads/4370264/normal_5f8e266eb173b.pdf
- https://xilorufanil.weebly.com/uploads/1/3/0/7/130739938/9007198.pdf
- https://satobolusiv.weebly.com/uploads/1/3/1/3/131398412/f0e4143d9.pdf
- https://cdn-cms.f-static.net/uploads/4366398/normal_5f88ced30bb18.pdf
- https://cdn-cms.f-static.net/uploads/4380223/normal_5f8bc60a88a7a.pdf
- https://cdn-cms.f-static.net/uploads/4365642/normal_5f8b585decc17.pdf
- https://cdn.shopify.com/s/files/1/0496/5295/7335/files/52284299824.pdf
- https://cdn.shopify.com/s/files/1/0428/2286/0956/files/toshiba_43l310u_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- firedisivimi.weebly.com
- tivakoxidedopa.weebly.com
- cdn-cms.f-static.net
- xilorufanil.weebly.com
- satobolusiv.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report