SUSPICIOUS — kupukow.pdf
SUSPICIOUS — kupukow.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
54fbb7217fd7c796d603769ccf967dae93c6cee828e44c449d9caba4fd0d9309 - SHA-1:
4bb0dd82a19b79e8175e1d5227fa76fdcd9cd852 - MD5:
3631448baae17dbd3c52473e857bf3d0 - ssdeep:
1536:8GFWD0rDfecDy8AEBqyLvp4h5VufQjYVdE12GxiGFmSXJWQE7CYhHUI:ZFWDkDnyH6qy94h5VufQjYPEUGxVFDXk - TLSH:
T1A038C1F301D3EC9C7AC67F036DAA146A3406C28A2237D664519C7B2D91BC2FDBE10865 - Submitted as: kupukow.pdf
- File type: pdf · Size: 76840 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://nizesuvijeva.weebly.com/uploads/1/3/1/6/131607023/podivedojowo.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=orwell%201984%20pdf%20libro, https://nizesuvijeva.weebly.com/uploads/1/3/1/6/131607023/podivedojowo.pdf, https://lugeluwad.weebly.com/uploads/1/3/4/3/134328935/farajasawufotidaf.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=orwell%201984%20pdf%20libro
- https://nizesuvijeva.weebly.com/uploads/1/3/1/6/131607023/podivedojowo.pdf
- https://lugeluwad.weebly.com/uploads/1/3/4/3/134328935/farajasawufotidaf.pdf
- https://uploads.strikinglycdn.com/files/6a32d329-d97e-4220-8d74-903eadc6430a/sidupituxas.pdf
- https://jugizefabugej.weebly.com/uploads/1/3/4/3/134377355/vemoligebajiguw.pdf
- https://uploads.strikinglycdn.com/files/7545feef-ecb5-4841-8d57-5deb8f1360da/create_an_airline_slogan_worksheet.pdf
- https://jarapitoxedomel.weebly.com/uploads/1/3/1/4/131437170/rotujajixaw-rugarim.pdf
- https://uploads.strikinglycdn.com/files/a367da4c-a3a8-4b53-9553-f8e78fa50c89/5828134998.pdf
- https://uploads.strikinglycdn.com/files/f7ae6e90-a41d-4c98-930f-f6983458dab6/mabuxadon.pdf
- https://s3.amazonaws.com/kiwopusafize/aviso_de_privacidad_estado_de_mexico.pdf
- https://uploads.strikinglycdn.com/files/afe163b7-0b7b-4921-bc6b-9545a744ab7d/12471142310.pdf
- https://vefavufarexuba.weebly.com/uploads/1/3/4/3/134315694/mubusuvajame_puramav.pdf
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/sefaritonos-nukivafeka-retisebop-regaxumex.pdf
- https://uploads.strikinglycdn.com/files/cb397389-161b-4341-94bc-ea477ca9726a/rulodurisedevod.pdf
- https://s3.amazonaws.com/rujimidujek/fuxibiwixi.pdf
- https://uploads.strikinglycdn.com/files/7c01a40e-ca42-4545-96c4-d57c5ac5ecc3/seminole_hard_rock_social_casino.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- nizesuvijeva.weebly.com
- lugeluwad.weebly.com
- uploads.strikinglycdn.com
- jugizefabugej.weebly.com
- jarapitoxedomel.weebly.com
- s3.amazonaws.com
- vefavufarexuba.weebly.com
- jawasolasazilem.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report