SUSPICIOUS — wanezadexavaw.pdf
SUSPICIOUS — wanezadexavaw.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c61067f30a1cb3c4c27b7a9dfb6b68776118787d4a6a86ae90ce3a897d8ce983 - SHA-1:
9fb3c13c1c04cf2477beb427200249147f9614df - MD5:
9bb729b33c796c00608c60813ffd4404 - ssdeep:
768:idgGzpDBpkiBgHvM0LTPJOEpdnTn/F5vY0RVNZ4HwQ0YLO88wdzbHE1Cv:xGF9pcnx4Hr/O8drE1Cv - TLSH:
T1C6316CF350A7DD8C3A878F136EEA246D6489D78861329B6050CC6B2CC47C7BE6F11961 - Submitted as: wanezadexavaw.pdf
- File type: pdf · Size: 40067 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=android%20french%20qwerty%20keyboard, https://cdn.shopify.com/s/files/1/0439/5086/6590/files/guideline_pet_ct_fdg.pdf, https://cdn.shopify.com/s/files/1/0496/6088/7203/files/20058837327.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=android%20french%20qwerty%20keyboard
- https://cdn.shopify.com/s/files/1/0439/5086/6590/files/guideline_pet_ct_fdg.pdf
- https://cdn.shopify.com/s/files/1/0496/6088/7203/files/20058837327.pdf
- https://cdn.shopify.com/s/files/1/0500/7484/5375/files/clever_mobile_call_recorder_apk.pdf
- https://cdn-cms.f-static.net/uploads/4369660/normal_5f89aa7f0f7d7.pdf
- https://cdn-cms.f-static.net/uploads/4366302/normal_5f89631c12bca.pdf
- https://cdn-cms.f-static.net/uploads/4366980/normal_5f8c88908893b.pdf
- https://cdn-cms.f-static.net/uploads/4367283/normal_5f874f5023d59.pdf
- https://cdn-cms.f-static.net/uploads/4369183/normal_5f89509c05fb2.pdf
- https://cdn-cms.f-static.net/uploads/4387701/normal_5f8ce454a593f.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_5f8765157ca17.pdf
- https://cdn-cms.f-static.net/uploads/4367631/normal_5f87460786cb3.pdf
- https://cdn-cms.f-static.net/uploads/4365536/normal_5f87f52d3b801.pdf
- https://cdn-cms.f-static.net/uploads/4369317/normal_5f8c5f570cb20.pdf
- https://cdn-cms.f-static.net/uploads/4365602/normal_5f87fa3c38062.pdf
- https://uploads.strikinglycdn.com/files/f81e26dc-149b-4159-b86e-7e9246f03114/nakuvafajamulezadavi.pdf
- https://uploads.strikinglycdn.com/files/43488a7e-804b-476c-8738-0150bef23665/42663335679.pdf
- https://uploads.strikinglycdn.com/files/0036205a-1399-403a-8f73-a6dcf35d9a06/punctuation_marks_quiz_with_answers.pdf
- https://uploads.strikinglycdn.com/files/06633a6f-638c-4005-b672-646e5539f7ff/o_peregrino_john_bunyan.pdf
- https://ditiwudo.weebly.com/uploads/1/3/1/4/131452947/wewipanudutulenukow.pdf
- https://dapujevubo.weebly.com/uploads/1/3/1/4/131438680/8114f4.pdf
- https://penulikadima.weebly.com/uploads/1/3/1/4/131482887/rikapugulepopaso.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- ditiwudo.weebly.com
- dapujevubo.weebly.com
- penulikadima.weebly.com
- www.google.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report