SUSPICIOUS — wegifaw.pdf
SUSPICIOUS — wegifaw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
8d1a6a18def577ea832c1a203f3683e85422d41c9913e78ffa6a78e48ddc19b8 - SHA-1:
5c3770891b6068826940b878ddfecc9a4e3616da - MD5:
60503b19cde86f0eaa0b73ce6c1a8370 - ssdeep:
768:TgGzpD7ew/je7CQzIxBrlQQdHWOKjicU9m5i9GJ92YRkUqERJ/tT0XsN0tfzC5yg:sGFHew63jbb7qUBlusm1C1uhg - TLSH:
T1C3337DF30097ED8C3A8BAF836DFB1199A14AD7892122E650059C772CC5BC6BD7F00A51 - Submitted as: wegifaw.pdf
- File type: pdf · Size: 49120 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=woods%20timer%20manual, https://cdn.shopify.com/s/files/1/0482/3508/5978/files/90454811565.pdf, https://cdn.shopify.com/s/files/1/0498/3272/2599/files/mettler_toledo_sevenexcellence_ph_conductivity_meter_manual.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=woods%20timer%20manual
- https://cdn.shopify.com/s/files/1/0482/3508/5978/files/90454811565.pdf
- https://cdn.shopify.com/s/files/1/0498/3272/2599/files/mettler_toledo_sevenexcellence_ph_conductivity_meter_manual.pdf
- https://cdn.shopify.com/s/files/1/0438/6534/2117/files/everett_alvarez_high_school_home_access_center.pdf
- https://cdn.shopify.com/s/files/1/0438/3683/3954/files/mining_software_repositories.pdf
- https://cdn.shopify.com/s/files/1/0498/9331/0631/files/3883418899.pdf
- https://cdn.shopify.com/s/files/1/0431/9477/7757/files/30716736324.pdf
- https://cdn.shopify.com/s/files/1/0460/0102/9279/files/precalculus_worksheet_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0497/4480/6042/files/2584501461.pdf
- https://cdn.shopify.com/s/files/1/0500/3178/8182/files/53838924853.pdf
- https://cdn.shopify.com/s/files/1/0434/1907/4722/files/training_plan_gym.pdf
- https://cdn.shopify.com/s/files/1/0496/3391/9127/files/creative_chili_names.pdf
- https://cdn.shopify.com/s/files/1/0481/6728/8989/files/miss_black_and_gold_pageant.pdf
- https://cdn.shopify.com/s/files/1/0499/0874/4381/files/docker_networking_tutorial.pdf
- https://uploads.strikinglycdn.com/files/4f5438d5-a74e-46ad-8ae8-a4338f7a656f/tupexujodamugefuza.pdf
- https://uploads.strikinglycdn.com/files/30fad9e0-8211-4ba4-9cf8-3b8bca0ba76e/84919994800.pdf
- https://uploads.strikinglycdn.com/files/78ab2f36-b86a-49bd-a264-adce30ede27f/56083880806.pdf
- https://uploads.strikinglycdn.com/files/ce3982a2-85a3-4c8d-878e-a7c19321943e/49605084694.pdf
- https://uploads.strikinglycdn.com/files/6abcdc22-5761-4280-8d39-ef9ac5c82613/32987326068.pdf
- https://uploads.strikinglycdn.com/files/77122d18-e5d0-4261-ad9a-b754f02e1c28/wwe_2k15_for_android_apk_data.pdf
- https://cdn.shopify.com/s/files/1/0486/3302/0584/files/5067989236.pdf
- https://cdn.shopify.com/s/files/1/0496/2189/3271/files/36243546576.pdf
- https://cdn.shopify.com/s/files/1/0499/3210/7937/files/tokabe.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/kofamokanolej.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report