SUSPICIOUS — javikupi.pdf
SUSPICIOUS — javikupi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
ca1de092b6afead09e6b58e946c99b186697724f2b28547719ce5d4e187433c9 - SHA-1:
86938bbe5f0572ca37b4cdd6b64207753760dac0 - MD5:
7713b88f77700a1d7892ef91efa402d8 - ssdeep:
768:xgGzpDnpr4FYNCileSewwkESWJd/RSnCKVkc0BBz7GFs+xMqI0BE:CGF7pr4FYUxcWn4nfkc0B5EdMR0BE - TLSH:
T110349DF3109BDD4C7AC7AB436AB72499A18AD7882062D7A044CD766CC47C7BE3F01A51 - Submitted as: javikupi.pdf
- File type: pdf · Size: 53907 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=asus%20hero%20alpha, https://uploads.strikinglycdn.com/files/4454c4bf-98c6-43d5-aa0d-b89839c17552/34736166139.pdf, https://uploads.strikinglycdn.com/files/68af9c95-f614-40eb-9c44-64e56645275c/mipugamosemopadusa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=asus%20hero%20alpha
- https://uploads.strikinglycdn.com/files/4454c4bf-98c6-43d5-aa0d-b89839c17552/34736166139.pdf
- https://uploads.strikinglycdn.com/files/68af9c95-f614-40eb-9c44-64e56645275c/mipugamosemopadusa.pdf
- https://uploads.strikinglycdn.com/files/3a58c476-6493-4ab7-9bc8-e14617040b14/diwanolivupasofavek.pdf
- https://uploads.strikinglycdn.com/files/8d3b91d3-b5c8-4353-ac9f-3713ea86c494/wamirupu.pdf
- https://uploads.strikinglycdn.com/files/8c3b38c4-693e-486b-9491-04acfeb29d59/62282897127.pdf
- https://uploads.strikinglycdn.com/files/02a58890-6db1-4494-a26f-134b2b5a87fc/lopigotavenu.pdf
- https://uploads.strikinglycdn.com/files/bc8772ee-d818-437c-b778-fc607d65b2b2/mobepakedavurego.pdf
- https://uploads.strikinglycdn.com/files/c9e8f4a3-e93e-4bcf-b595-7ae3c570a3ab/8640821101.pdf
- https://uploads.strikinglycdn.com/files/02181e6f-9bab-4d02-a0f5-9a719b97e0d1/gigogimunuvebefizup.pdf
- https://uploads.strikinglycdn.com/files/0cf5d386-ddc5-4533-8dca-934312fa85a6/72733062670.pdf
- https://uploads.strikinglycdn.com/files/17132135-5f76-49fb-aa7d-5ce0abe16379/23433616243.pdf
- https://kinojapi.weebly.com/uploads/1/3/2/3/132302846/bezofusijalefu.pdf
- https://medizagokitoni.weebly.com/uploads/1/3/2/3/132303310/c558058877e76a9.pdf
- https://wirukibit.weebly.com/uploads/1/3/0/9/130969322/d0e73e.pdf
- https://wopeduvolevim.weebly.com/uploads/1/3/0/7/130776212/6281626.pdf
- https://zesopupejilit.weebly.com/uploads/1/3/0/7/130738861/66666e4d6f5.pdf
- https://wesujugureju.weebly.com/uploads/1/3/0/8/130874517/pakotusadezidudu.pdf
- https://uploads.strikinglycdn.com/files/2bfa9b3d-7fad-4f31-b4df-6bc08007fb28/juxasime.pdf
- https://uploads.strikinglycdn.com/files/c9df5296-0611-4b15-bd07-47941b3b98f5/xumuborunok.pdf
- https://uploads.strikinglycdn.com/files/ee37e8e1-f244-4a7d-b3cf-09b116f90d10/10791732921.pdf
- https://uploads.strikinglycdn.com/files/ca95b4c8-5871-429f-ab63-51503314d9e8/vukaxakinik.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- kinojapi.weebly.com
- medizagokitoni.weebly.com
- wirukibit.weebly.com
- wopeduvolevim.weebly.com
- zesopupejilit.weebly.com
- wesujugureju.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report