SUSPICIOUS — kaguse.pdf
SUSPICIOUS — kaguse.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
cdb783f7386662dafb1f085bfa92bcbb7b4f9ee22449cea1b959bee672c133c2 - SHA-1:
b07ecad5650fb1cdb90c773086c954c4586aeaeb - MD5:
88e2dd4821278fbbbd741c095b63c562 - ssdeep:
1536:yGFKKcrEEznnZjeoZJChG/Tv2r98crzNkOx:rFK7gUnn4i/T+98c/h - TLSH:
T13434CFFBA4ABED0D7A96AB03AEBE0499204DC388B072D6B059D4777CC4BC5DD6D00911 - Submitted as: kaguse.pdf
- File type: pdf · Size: 53240 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=cranial%20nerve%20table%20review%20worksheet, https://uploads.strikinglycdn.com/files/4d0577cb-21a1-4c38-bef5-ac0c65877469/26440407453.pdf, https://uploads.strikinglycdn.com/files/967c5f2a-3727-4c12-8c84-7f8050cc5fb5/rimeludanojigerub.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=cranial%20nerve%20table%20review%20worksheet
- https://gogajajar.files.wordpress.com/2020/11/48539197016.pdf
- https://uploads.strikinglycdn.com/files/4d0577cb-21a1-4c38-bef5-ac0c65877469/26440407453.pdf
- https://bekagitowura373027609.files.wordpress.com/2020/11/pazutugatuw.pdf
- https://uploads.strikinglycdn.com/files/967c5f2a-3727-4c12-8c84-7f8050cc5fb5/rimeludanojigerub.pdf
- https://uploads.strikinglycdn.com/files/d05769f7-f567-4edb-8387-c4894fb29dbf/gunetoxewumebetu.pdf
- https://davametafa.files.wordpress.com/2020/11/bone_tomahawk_death_scene.pdf
- https://uploads.strikinglycdn.com/files/7e213098-4693-41ce-8618-58dd82cc1ae8/1411512496.pdf
- https://uploads.strikinglycdn.com/files/000ebc81-3d51-4ed8-8d76-cc93cbf1801c/11602295090.pdf
- https://uploads.strikinglycdn.com/files/c9cf43a0-3577-4141-88b3-bc1180caf117/sannathiyil_kattum_katti_video_song.pdf
- https://uploads.strikinglycdn.com/files/5ec5b75c-e49c-4af8-9613-8f9ea7d2bf5b/hamlet_internal_conflict.pdf
- https://punotajevi.weebly.com/uploads/1/3/4/2/134266109/96eaf7.pdf
- https://tegorijike.files.wordpress.com/2020/11/kogama_hack_gold_and_silver_generator.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- gogajajar.files.wordpress.com
- uploads.strikinglycdn.com
- bekagitowura373027609.files.wordpress.com
- davametafa.files.wordpress.com
- punotajevi.weebly.com
- tegorijike.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report