SUSPICIOUS — gowinuvu.pdf
SUSPICIOUS — gowinuvu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
0916f77820e46c67c0863ddc6b252fbd9611319363d7dd0b06f18b9993f269bd - SHA-1:
b16bb284e0a7bc04df2caddac00494f0a540f5d1 - MD5:
16eae1311fa909d69d73e34ce24f9a51 - ssdeep:
768:ggGzpDypyFXMmaYDJrueTJ5HwFtYu9+3hMk9cF+zVoiuzn:tGF2p01ON03hzogoiuzn - TLSH:
T18E328EF7149BDC4C7E8BAB03E9A71695018AD28C6227D350498C372DD4BCAFE7E00561 - Submitted as: gowinuvu.pdf
- File type: pdf · Size: 43708 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=changing%20decimal%20to%20percent%20worksheet, https://uploads.strikinglycdn.com/files/888b16d3-e076-45f2-8a25-6efd3b786cae/35146629898.pdf, https://uploads.strikinglycdn.com/files/b7a6d329-41e6-4c83-a028-a54180d98dee/jolenogemu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=changing%20decimal%20to%20percent%20worksheet
- https://s3.amazonaws.com/kudowo/13247079581.pdf
- https://s3.amazonaws.com/wonoti/blended_book_sharon_draper.pdf
- https://s3.amazonaws.com/pazifetanegapu/al_quran_bangla_darussalam.pdf
- https://s3.amazonaws.com/vexeliku/89735365607.pdf
- https://s3.amazonaws.com/zetare/gta_5_cheat_codes_for_pc.pdf
- https://uploads.strikinglycdn.com/files/888b16d3-e076-45f2-8a25-6efd3b786cae/35146629898.pdf
- https://uploads.strikinglycdn.com/files/b7a6d329-41e6-4c83-a028-a54180d98dee/jolenogemu.pdf
- https://uploads.strikinglycdn.com/files/f6f05b0e-7cae-4dcf-9f64-db99877b1512/89242803117.pdf
- https://uploads.strikinglycdn.com/files/6b920ffc-c82b-447d-83fe-be49ce000ecf/70266421319.pdf
- https://uploads.strikinglycdn.com/files/8da6b9c9-c0f5-4d77-aa9c-b14763f5529d/step_up_medicine_in_nepal.pdf
- https://cdn.shopify.com/s/files/1/0431/9569/5265/files/vafikurabi.pdf
- https://cdn.shopify.com/s/files/1/0428/8479/2479/files/proper_deposition_objections_florida.pdf
- https://uploads.strikinglycdn.com/files/af87d352-ac9b-42f5-9da2-7f505bb9eb6c/xizufamodabafup.pdf
- https://uploads.strikinglycdn.com/files/784c4c0e-0a74-4710-bb11-ccabc0d847de/39833971266.pdf
- https://uploads.strikinglycdn.com/files/a2d8e4b1-529e-4e7f-b2f4-97eaa220c8fc/83137518808.pdf
- https://cdn.shopify.com/s/files/1/0502/1876/2415/files/42692288609.pdf
- https://cdn.shopify.com/s/files/1/0429/0638/6595/files/pitch_perfect_3_script.pdf
- https://cdn.shopify.com/s/files/1/0500/0370/6006/files/wipasesa.pdf
- https://cdn-cms.f-static.net/uploads/4383322/normal_5f9240d7e1288.pdf
- https://cdn-cms.f-static.net/uploads/4367656/normal_5f88924b5a1b7.pdf
- https://cdn-cms.f-static.net/uploads/4367674/normal_5f889fd759454.pdf
- https://cdn-cms.f-static.net/uploads/4385613/normal_5f914d75a2428.pdf
- https://cdn-cms.f-static.net/uploads/4377928/normal_5f8a087913cf1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn.shopify.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report