SUSPICIOUS — wagikawogutix.pdf
SUSPICIOUS — wagikawogutix.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
a06851c190babbef12617cdd8486449ebcf25d526123996c629114882291d39b - SHA-1:
5433026e46f9bea1888f0197361b54e0e218aeed - MD5:
6f986554b6751385e7c9d6d6a12a1242 - ssdeep:
768:ggGzpDkpTGfK+jTpct5lv/H902YVoFsBHY/ZjsVR8lcThAXBkJ2U6p4u5L:tGFopKF/ps+Hyps51WA2Uu4u5L - TLSH:
T156349EF300A3EE4C7A8B7F07ADEB11996049D38C6136AB905588772CD0BCBED6E50651 - Submitted as: wagikawogutix.pdf
- File type: pdf · Size: 52957 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=trials%20of%20apollo%20book%202%20pdf, https://cdn.shopify.com/s/files/1/0430/7222/5442/files/jeanne_wakatsuki_houston_family.pdf, https://cdn.shopify.com/s/files/1/0266/8586/6167/files/mijasaloniruvozo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=trials%20of%20apollo%20book%202%20pdf
- https://cdn.shopify.com/s/files/1/0430/7222/5442/files/jeanne_wakatsuki_houston_family.pdf
- https://cdn.shopify.com/s/files/1/0266/8586/6167/files/mijasaloniruvozo.pdf
- https://cdn.shopify.com/s/files/1/0482/2083/1904/files/getefor.pdf
- https://cdn.shopify.com/s/files/1/0433/0101/1611/files/21981957644.pdf
- https://cdn.shopify.com/s/files/1/0438/2231/7728/files/funciones_exponenciales_resueltas.pdf
- https://uploads.strikinglycdn.com/files/22356fd3-79a0-4db3-9d06-315c98137efa/vafakilinajenolapokojaja.pdf
- https://uploads.strikinglycdn.com/files/3c6dd74b-d005-4ed9-8fc7-0af5df368756/dirufat.pdf
- https://uploads.strikinglycdn.com/files/efe3a271-a294-497d-970e-a051be919a3f/85240458609.pdf
- https://uploads.strikinglycdn.com/files/129a8639-66a2-46d9-abbd-e65afabe47a7/zumekisepulareni.pdf
- https://cdn-cms.f-static.net/uploads/4365542/normal_5f8786dcbdc3b.pdf
- https://cdn-cms.f-static.net/uploads/4368964/normal_5f878cfc69caa.pdf
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f87509116163.pdf
- https://cdn-cms.f-static.net/uploads/4366041/normal_5f875ba961994.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f879d495aa2b.pdf
- https://site-1042886.mozfiles.com/files/1042886/plastic_lace_bracelet_instructions.pdf
- https://site-1043910.mozfiles.com/files/1043910/juvijudugebejitijun.pdf
- https://site-1043337.mozfiles.com/files/1043337/74271377190.pdf
- https://site-1037160.mozfiles.com/files/1037160/golulur.pdf
- https://site-1043458.mozfiles.com/files/1043458/11604623419.pdf
- https://uploads.strikinglycdn.com/files/912cf912-3c68-4735-ac6e-a609a891c677/kelezerujigokikuzodume.pdf
- https://uploads.strikinglycdn.com/files/87a5ca0d-e7b8-4220-a87e-b7ba7bef52b3/80936269449.pdf
- https://site-1040242.mozfiles.com/files/1040242/86951687557.pdf
- https://site-1039954.mozfiles.com/files/1039954/gudenirezuranuvon.pdf
- https://site-1039273.mozfiles.com/files/1039273/42276633027.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- site-1042886.mozfiles.com
- site-1043910.mozfiles.com
- site-1043337.mozfiles.com
- site-1037160.mozfiles.com
- site-1043458.mozfiles.com
- site-1040242.mozfiles.com
- site-1039954.mozfiles.com
- site-1039273.mozfiles.com
- site-1038794.mozfiles.com
- site-1039129.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report