SUSPICIOUS — kutozokifabedumofisesugop.pdf
SUSPICIOUS — kutozokifabedumofisesugop.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
d9dc6dd755be473f130fbd0ab32e80e30bbd0aa816d02bcf9c812c4def4237f4 - SHA-1:
7bd0ea9ce4caba7815ad42e53851c30030d40dd2 - MD5:
0303bba5973b03f38e30acdc376abf29 - ssdeep:
768:MgGzpD+phxm30gEaC6eTmK9D8nwTLkf06nGrHkH2veB9PoboUlOA:JGFqppT8nWLoYxeDPoEUlOA - TLSH:
T18231AFF3109BEC8D3AC59B03ACE904666189C38D7126D7B458E87B6CC4BC6FD6D10961 - Submitted as: kutozokifabedumofisesugop.pdf
- File type: pdf · Size: 42757 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=russian+language+letters+pdf, https://cdn.shopify.com/s/files/1/0437/7578/7157/files/indian_restaurants_near_space_needle.pdf, https://cdn.shopify.com/s/files/1/0496/4869/7493/files/nudos_y_amarres.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=russian+language+letters+pdf
- https://cdn.shopify.com/s/files/1/0437/7578/7157/files/indian_restaurants_near_space_needle.pdf
- https://cdn.shopify.com/s/files/1/0496/4869/7493/files/nudos_y_amarres.pdf
- https://cdn.shopify.com/s/files/1/0434/1540/4695/files/tucson_high_magnet_school_course_catalog.pdf
- https://cdn.shopify.com/s/files/1/0432/4560/0936/files/zumisepukisidibatifesebaw.pdf
- https://cdn.shopify.com/s/files/1/0437/3908/7002/files/bitunupofamotire.pdf
- http://rapuduvo.shimsfitness.com/uploads/1/3/2/8/132814930/5134985.pdf
- http://files.tiftcountysoccer.com/uploads/1/3/1/6/131606121/5562176.pdf
- http://nolewajax.thomasmeloro.com/uploads/1/3/1/3/131379639/dff597.pdf
- https://cdn.shopify.com/s/files/1/0483/5291/9703/files/watermark_in_excel_sheet.pdf
- https://cdn.shopify.com/s/files/1/0483/6245/5191/files/counting_atoms_worksheet.pdf
- https://cdn.shopify.com/s/files/1/0436/9701/2890/files/chapter_4_triangle_congruence_cumulative_test_answers.pdf
- https://cdn.shopify.com/s/files/1/0433/1362/7294/files/chronicler_seal_destiny_2_guide.pdf
- https://cdn.shopify.com/s/files/1/0437/5429/1361/files/gukemetebimejunuw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- rapuduvo.shimsfitness.com
- files.tiftcountysoccer.com
- nolewajax.thomasmeloro.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report