SUSPICIOUS — gokupukutev.pdf
SUSPICIOUS — gokupukutev.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
aa5dfcea5016068f56596b7dd4e81be2ea49bd9e090914e228d9d12ee802a594 - SHA-1:
0903ba6594e221ce51046fc423c49316bff93e79 - MD5:
605022302fb738db207b18cb063e1595 - ssdeep:
768:qmgGzpDMeBmrE0lF32ZdGKHADELEDvmx3vAO5Vab9yRgDNkAFqk2gNqBtfhobPZ9:YGFQeBi8v3z5wJAk/QXhqPZUNgj - TLSH:
T114328DF314A7ED4C7A8AD703ADBB10A5648AC78C61379790448C6B2CD5BC6BD6E10A50 - Submitted as: gokupukutev.pdf
- File type: pdf · Size: 45783 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=the%20amazing%20spider%20man%20apk%20download%20for%20android, https://fevixivosetakub.weebly.com/uploads/1/3/2/6/132681861/setusutusogudagapeko.pdf, https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/b628c54eef4e3.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=the%20amazing%20spider%20man%20apk%20download%20for%20android
- https://fevixivosetakub.weebly.com/uploads/1/3/2/6/132681861/setusutusogudagapeko.pdf
- https://zafozudakajadev.weebly.com/uploads/1/3/0/8/130814863/b628c54eef4e3.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/134863603f.pdf
- https://fumadutukit.weebly.com/uploads/1/3/1/4/131437402/vosituvemap.pdf
- https://cdn-cms.f-static.net/uploads/4366337/normal_5f875e5925f0b.pdf
- https://cdn-cms.f-static.net/uploads/4368985/normal_5f879decaab3a.pdf
- https://cdn-cms.f-static.net/uploads/4366407/normal_5f87fd10ea2c9.pdf
- https://cdn.shopify.com/s/files/1/0266/9789/2031/files/wiboxek.pdf
- https://cdn.shopify.com/s/files/1/0498/9390/0455/files/82277704835.pdf
- https://cdn.shopify.com/s/files/1/0430/7622/3129/files/85105382015.pdf
- https://cdn.shopify.com/s/files/1/0494/2263/1067/files/navy_nec_code_805a.pdf
- https://cdn.shopify.com/s/files/1/0430/7619/0361/files/75272628892.pdf
- https://cdn-cms.f-static.net/uploads/4369920/normal_5f8865ca3a604.pdf
- https://cdn-cms.f-static.net/uploads/4366031/normal_5f8703bdd32dc.pdf
- https://cdn-cms.f-static.net/uploads/4366987/normal_5f89149865604.pdf
- https://cdn-cms.f-static.net/uploads/4369932/normal_5f885f748ec1f.pdf
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f88d50d54f13.pdf
- https://cdn.shopify.com/s/files/1/0495/4914/8312/files/rawuwetadewonetaw.pdf
- https://cdn.shopify.com/s/files/1/0483/9597/6856/files/greyhound_package_tracking_canada.pdf
- https://uploads.strikinglycdn.com/files/1ec807dd-b582-4530-998d-d378a0396ee0/44908094625.pdf
- https://uploads.strikinglycdn.com/files/efea9a3f-14eb-4715-ae44-aaed8954eb57/18945598880.pdf
- https://uploads.strikinglycdn.com/files/558dee6d-243a-4eef-b92f-e86075344ff2/9029597743.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- ggtraff.ru
- fevixivosetakub.weebly.com
- zafozudakajadev.weebly.com
- juragubiv.weebly.com
- fumadutukit.weebly.com
- cdn-cms.f-static.net
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report