SUSPICIOUS — fupepukak.pdf
SUSPICIOUS — fupepukak.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
c0d65d4c2de3c83a65067612046b96c0aee6967d0422c0f9b2abe3831017a1f4 - SHA-1:
e476a055ba1d7b4e7a536a50a01508d26f12a259 - MD5:
b8512a605d97e3d49356163a279e2d5a - ssdeep:
768:SgGzpDHev+bKZSA+Y/iBloXeWt2lHuhiT2dmvPkzObBqi5y7mVNgg:PGFbeGUcTumbbBqiMWyg - TLSH:
T17E317CF3109BED4C7A8B9B43ADEB005D5049C78D2136DA904488772CE57CAFEBE50A21 - Submitted as: fupepukak.pdf
- File type: pdf · Size: 40856 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=alfred, https://cdn.shopify.com/s/files/1/0498/4035/7538/files/noticings_and_wonderings.pdf, https://cdn.shopify.com/s/files/1/0477/6201/4364/files/jiworux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=alfred
- https://cdn.shopify.com/s/files/1/0498/4035/7538/files/noticings_and_wonderings.pdf
- https://cdn.shopify.com/s/files/1/0477/6201/4364/files/jiworux.pdf
- https://cdn.shopify.com/s/files/1/0499/8683/0496/files/contingencies_of_reinforcement_rbt.pdf
- https://cdn.shopify.com/s/files/1/0498/6440/9243/files/besitos_de_coco.pdf
- https://site-1043704.mozfiles.com/files/1043704/jarevupelumu.pdf
- https://site-1038874.mozfiles.com/files/1038874/30580577387.pdf
- https://site-1041084.mozfiles.com/files/1041084/34290502593.pdf
- https://site-1042590.mozfiles.com/files/1042590/bivowovekinuv.pdf
- https://site-1039801.mozfiles.com/files/1039801/71057296342.pdf
- https://site-1043885.mozfiles.com/files/1043885/90231749207.pdf
- https://site-1039549.mozfiles.com/files/1039549/fuxujebafisularipa.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_5f86f4c78e134.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f86f73765d37.pdf
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f871c0b29547.pdf
- https://cdn.shopify.com/s/files/1/0501/8019/4459/files/pulmonary_circulation_and_systemic_circulation.pdf
- https://cdn.shopify.com/s/files/1/0499/3066/6152/files/bass_clef_acronym_aceg.pdf
- https://cdn.shopify.com/s/files/1/0434/5603/7017/files/glencoe_world_history_answer_key.pdf
- https://cdn.shopify.com/s/files/1/0463/3555/7794/files/dagenela.pdf
- https://cdn.shopify.com/s/files/1/0482/8122/3336/files/zte_z812_network_unlock_code_free.pdf
- https://cdn.shopify.com/s/files/1/0461/8122/0505/files/46696562530.pdf
- https://cdn.shopify.com/s/files/1/0496/1258/7159/files/pawagasetasumima.pdf
- https://cdn.shopify.com/s/files/1/0498/6624/4251/files/nimamida.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- gettraff.ru
- cdn.shopify.com
- site-1043704.mozfiles.com
- site-1038874.mozfiles.com
- site-1041084.mozfiles.com
- site-1042590.mozfiles.com
- site-1039801.mozfiles.com
- site-1043885.mozfiles.com
- site-1039549.mozfiles.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report