SUSPICIOUS — kuvopom.pdf
SUSPICIOUS — kuvopom.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
211d08e027e21700fd2f52663a479477fb0e69d6b443cffc609f8f9207dab4d5 - SHA-1:
ac77da25daaa9d6cb629b4d2a72ca0d9ccfea227 - MD5:
011b228cb7ee94ebe221b537778e819a - ssdeep:
1536:cGFap09rfhrMBEcfpRxMgpwIwBAFgFb/CBPg5ITdcXew4:5Fap0Bhrq/RxVpwIQFb6OO8o - TLSH:
T12637C0F355A3EC5C79872F17AEEB11A8D44AD24CA0319B608488773CC4BC6FE6E005A5 - Submitted as: kuvopom.pdf
- File type: pdf · Size: 72202 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=athens%20and%20sparta%20economy, https://cdn-cms.f-static.net/uploads/4367646/normal_5f88bd0b3ef41.pdf, https://cdn-cms.f-static.net/uploads/4366008/normal_5f87380717cee.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=athens%20and%20sparta%20economy
- https://cdn-cms.f-static.net/uploads/4367646/normal_5f88bd0b3ef41.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f87380717cee.pdf
- https://cdn-cms.f-static.net/uploads/4365656/normal_5f88c0aacf30c.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f8757bdd9107.pdf
- https://cdn-cms.f-static.net/uploads/4366395/normal_5f871c0bba8ed.pdf
- https://cdn-cms.f-static.net/uploads/4366336/normal_5f880ea250dc1.pdf
- https://cdn-cms.f-static.net/uploads/4366010/normal_5f87c2fee94c0.pdf
- https://cdn-cms.f-static.net/uploads/4365620/normal_5f874300a4aaa.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_5f88bc62ccd37.pdf
- https://vawotitalu.weebly.com/uploads/1/3/2/7/132710714/2332972.pdf
- https://zevigetadafuwun.weebly.com/uploads/1/3/0/9/130969942/venituvibuzukiwed.pdf
- https://zevigetadafuwun.weebly.com/uploads/1/3/0/9/130969942/4595a3c31d507.pdf
- https://cdn-cms.f-static.net/uploads/4366632/normal_5f87280f7679d.pdf
- https://cdn-cms.f-static.net/uploads/4368225/normal_5f88c20323667.pdf
- https://site-1038326.mozfiles.com/files/1038326/23989229662.pdf
- https://site-1043970.mozfiles.com/files/1043970/6067746576.pdf
- https://site-1040438.mozfiles.com/files/1040438/nijulopi.pdf
- https://site-1048576.mozfiles.com/files/1048576/gopabekoremogetonuga.pdf
- https://site-1040221.mozfiles.com/files/1040221/gitiguvatenen.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- vawotitalu.weebly.com
- zevigetadafuwun.weebly.com
- site-1038326.mozfiles.com
- site-1043970.mozfiles.com
- site-1040438.mozfiles.com
- site-1048576.mozfiles.com
- site-1040221.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report