SUSPICIOUS — wogafij.pdf
SUSPICIOUS — wogafij.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
90f735a1696f8d690822f8e9059e910afc4eb2f0f7ac7d34da5918d779e7f2a3 - SHA-1:
12cdc4665df45dbc300b6ab5032b4d44cc50ac06 - MD5:
5a3c9ec045fe760bf752f959d1f82bdd - ssdeep:
768:OgGzpDYp9g+ngfzRfdeOdvMWEsAQk8iWUD98F7J63vdVs4U+RlDp:rGFMpi+n4u98Fl63vz++RlDp - TLSH:
T13C317CF39497ED8DBA879B036CAB216D114DC2886236D760588C7B2DD0BC6BD7F14860 - Submitted as: wogafij.pdf
- File type: pdf · Size: 39678 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=datsun%20240z%20workshop%20manual, https://cdn-cms.f-static.net/uploads/4365563/normal_5f87167447c72.pdf, https://cdn-cms.f-static.net/uploads/4366369/normal_5f873f6464018.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=datsun%20240z%20workshop%20manual
- https://cdn-cms.f-static.net/uploads/4365563/normal_5f87167447c72.pdf
- https://cdn-cms.f-static.net/uploads/4366369/normal_5f873f6464018.pdf
- https://cdn-cms.f-static.net/uploads/4365582/normal_5f89785ebe108.pdf
- https://cdn-cms.f-static.net/uploads/4372681/normal_5f88d7ce8bc8b.pdf
- https://cdn.shopify.com/s/files/1/0484/6875/4594/files/bunker_hill_security_digital_safe_manual.pdf
- https://uploads.strikinglycdn.com/files/f41bad00-acbc-41b8-bf82-32434625f1e9/futolefadasi.pdf
- https://uploads.strikinglycdn.com/files/458ae664-c179-4866-86e7-e66fcac6dfc1/tinimuxevegizeveselulurup.pdf
- https://uploads.strikinglycdn.com/files/7a981d75-97cf-45d7-a4f2-6dcc1b0cade6/9388566288.pdf
- https://uploads.strikinglycdn.com/files/59a98cf9-35fe-475c-853a-351483ddcf73/2002008202.pdf
- https://uploads.strikinglycdn.com/files/e004845d-81ec-4ced-93ee-34da79a82b0d/34175220656.pdf
- https://cdn.shopify.com/s/files/1/0483/5681/9097/files/amplitude_period_phase_shift_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0433/4426/5366/files/rixis.pdf
- https://cdn.shopify.com/s/files/1/0266/8517/8052/files/77686984845.pdf
- https://cdn.shopify.com/s/files/1/0440/4012/6614/files/spectrum_tv_app_guide_settings.pdf
- https://cdn.shopify.com/s/files/1/0484/9008/6561/files/budagemujebuwuremubikupe.pdf
- https://uploads.strikinglycdn.com/files/3bf891f9-b187-4075-8424-c84b0587cd54/gexowitu.pdf
- https://uploads.strikinglycdn.com/files/10455a9b-7aab-4229-a947-869110407775/fugisefunurixewiza.pdf
- https://uploads.strikinglycdn.com/files/aa1302f3-933b-4236-ad63-ce22525dd8bf/91289581446.pdf
- https://uploads.strikinglycdn.com/files/23569c7b-0a14-4ff8-9872-1c5dd6917cd9/35673280005.pdf
- https://cdn.shopify.com/s/files/1/0496/5990/4157/files/lomasazoribuwovijamu.pdf
- https://cdn.shopify.com/s/files/1/0501/1380/6486/files/78085036870.pdf
- https://cdn.shopify.com/s/files/1/0493/0669/7887/files/what_to_do_if_my_roku_remote_doesnt_have_a_pairing_button.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report