SUSPICIOUS — wamivi.pdf
SUSPICIOUS — wamivi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
412c8567b484e8aa6910ffca2068c71c7f00beb47b02eaaed1d86f373113a44e - SHA-1:
314150c047ff09907cc8de053ff9fdf4b8a01dc5 - MD5:
bae526488416b8985815467c3878b3a2 - ssdeep:
768:AgGzpDHpJhgnae3a/fOsCUfiMJHhmgcmin3RNP+gKWKwQSRcqjWFqU2G:NGFTpPenmy/+g2wQUcjcU2G - TLSH:
T188328EF310B7ED8C7A8BAB13ADA71159A049C3896026EB51448C772CE47C7ED7E10A61 - Submitted as: wamivi.pdf
- File type: pdf · Size: 46393 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=read%20a%20file%20in%20c, https://cdn.shopify.com/s/files/1/0498/7994/1278/files/90459931296.pdf, https://cdn.shopify.com/s/files/1/0437/6500/6494/files/63904037253.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=read%20a%20file%20in%20c
- https://cdn.shopify.com/s/files/1/0498/7994/1278/files/90459931296.pdf
- https://cdn.shopify.com/s/files/1/0483/6727/2087/files/15439385133.pdf
- https://cdn.shopify.com/s/files/1/0437/6500/6494/files/63904037253.pdf
- https://cdn.shopify.com/s/files/1/0484/8707/1906/files/nature_of_science_worksheet_5th_grade.pdf
- https://cdn.shopify.com/s/files/1/0484/2009/4104/files/vowodepowofi.pdf
- https://cdn-cms.f-static.net/uploads/4366365/normal_5f87b098b85d1.pdf
- https://cdn-cms.f-static.net/uploads/4366316/normal_5f875ad446f20.pdf
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f875917a2e6c.pdf
- https://cdn-cms.f-static.net/uploads/4367271/normal_5f87bab49c19d.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f870ddccca98.pdf
- https://uploads.strikinglycdn.com/files/7054c1be-7d8f-4753-8d8f-787a4d509e63/64065887533.pdf
- https://uploads.strikinglycdn.com/files/91eeaa45-63ac-453f-b559-a7eb6ff3494b/larupafulowomazolet.pdf
- https://uploads.strikinglycdn.com/files/dd8d9940-1b0a-47a9-b203-6a2f598bf5c3/fuvajojonizox.pdf
- https://uploads.strikinglycdn.com/files/f28c4422-e57a-4100-98d0-1ddd8f1a18a9/3083123166.pdf
- https://uploads.strikinglycdn.com/files/cea23383-80d0-45d7-9883-3e000db8c838/kanalis.pdf
- https://cdn-cms.f-static.net/uploads/4366311/normal_5f874038749af.pdf
- https://cdn-cms.f-static.net/uploads/4366312/normal_5f872bb5f295f.pdf
- https://cdn-cms.f-static.net/uploads/4365547/normal_5f87e470cd755.pdf
- https://site-1038739.mozfiles.com/files/1038739/48361122826.pdf
- https://site-1041611.mozfiles.com/files/1041611/82312666679.pdf
- https://site-1042917.mozfiles.com/files/1042917/84703659369.pdf
- https://site-1043128.mozfiles.com/files/1043128/65991535211.pdf
- https://site-1038999.mozfiles.com/files/1038999/31730059323.pdf
- https://site-1042671.mozfiles.com/files/1042671/plane_strain_and_plane_stress.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- site-1038739.mozfiles.com
- site-1041611.mozfiles.com
- site-1042917.mozfiles.com
- site-1043128.mozfiles.com
- site-1038999.mozfiles.com
- site-1042671.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report