SUSPICIOUS — kowupa-nufud.pdf
SUSPICIOUS — kowupa-nufud.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
54dbde629e91398f602933cb07251bb25e786eb6cc2890cdea46c6c8ae23c779 - SHA-1:
92c02b0d6615a2c3a9affce2d9cc6ffdc458fd18 - MD5:
c4afbcb3a19ed1fee8993228a6a84d6f - ssdeep:
1536:OGFCpXOlQ0RNOp/TH9Js58fFocGirP6hlyIfCWTAZ5u:3FCpelZAR9h4YWUO - TLSH:
T15636CFF76497EE5D7AC78F13DDBB149E214AD688A133AB9104C8676CC47C2AC5E21820 - Submitted as: kowupa-nufud.pdf
- File type: pdf · Size: 68967 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=seaweed%20extracts%20as%20biostimulants%20of%20plant%20growth%20and%20development%20pdf, https://cdn-cms.f-static.net/uploads/4366009/normal_5f8be02aaf8ec.pdf, https://cdn-cms.f-static.net/uploads/4383295/normal_5f8db33eca81b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=seaweed%20extracts%20as%20biostimulants%20of%20plant%20growth%20and%20development%20pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f8be02aaf8ec.pdf
- https://cdn-cms.f-static.net/uploads/4383295/normal_5f8db33eca81b.pdf
- https://cdn-cms.f-static.net/uploads/4393345/normal_5f91f40a8ade4.pdf
- https://uploads.strikinglycdn.com/files/7715b3d8-40d5-4658-9022-5092b1487d14/dizawiremotojajuvubivate.pdf
- https://uploads.strikinglycdn.com/files/e73b8c9e-52e7-42fb-92f3-a69768692fe8/55745672529.pdf
- https://uploads.strikinglycdn.com/files/0a209b49-9590-4a79-9c53-2061a3afe5fb/jalijizaxo.pdf
- https://uploads.strikinglycdn.com/files/0077dc4a-b17f-4374-8696-1287d96635ec/zewuwomaxunitifarapitaf.pdf
- https://uploads.strikinglycdn.com/files/c92c69fe-7172-453c-b05d-8d8994b629af/business_essentials_11th_edition.pdf
- https://cdn.shopify.com/s/files/1/0502/0228/0119/files/the_economist_democracy_index.pdf
- https://cdn.shopify.com/s/files/1/0499/8837/0582/files/6436585377.pdf
- https://cdn.shopify.com/s/files/1/0500/6698/1013/files/29764547880.pdf
- https://cdn.shopify.com/s/files/1/0432/1784/6427/files/bezorinumiputun.pdf
- https://s3.amazonaws.com/wibadinavosunom/aadhaar_data_update_form_download.pdf
- https://s3.amazonaws.com/leguvefu/wopifamijo.pdf
- https://s3.amazonaws.com/sugaguxagu/el_bullying_causas_y_consecuencias.pdf
- https://s3.amazonaws.com/tiluwisulepam/structure_and_function_of_atp_synthase.pdf
- https://s3.amazonaws.com/leguvefu/cultura_geral_sobre_angola.pdf
- https://uploads.strikinglycdn.com/files/6abd2b42-019c-4f9a-a2ea-be5ac405710c/konijiwapo.pdf
- https://uploads.strikinglycdn.com/files/15187f76-be48-4128-bcd4-f314408c23d0/romaritas.pdf
- https://cdn-cms.f-static.net/uploads/4393514/normal_5f91fc3f1a003.pdf
- https://cdn-cms.f-static.net/uploads/4386593/normal_5f8e78f9a2e1c.pdf
- https://cdn-cms.f-static.net/uploads/4366385/normal_5f875cc4398d4.pdf
- https://cdn-cms.f-static.net/uploads/4375891/normal_5f89f63071903.pdf
- https://cdn-cms.f-static.net/uploads/4368225/normal_5f8ab0d66535d.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report