SUSPICIOUS — kikumapiti.pdf
SUSPICIOUS — kikumapiti.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
da61c2d1fb62137d6814e0ca82ccee80a5495fa19a18d32784a49261204c95a6 - SHA-1:
850c25f4595cd112aa616ab7560f308239e66f22 - MD5:
ddba69dcb54f24dddb7a5b589ab0a8e2 - ssdeep:
3072:HFVeqpiWPMaKW/DkBuUeZWGA/gZA3gyQNbo2Kg4q:lcOioKwDkBF7GA/qY2l - TLSH:
T1843BD0F3609BDD8C79C79783B9B610A52449CB883172E7A0448C7ABCC87C67D6F50A91 - Submitted as: kikumapiti.pdf
- File type: pdf · Size: 104472 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=resident%20evil%204%20ps2%20manual, https://uploads.strikinglycdn.com/files/f83e0226-83bb-4ba5-a83b-8a24415f55ca/EPF_odstpenie_na_50.pdf, https://uploads.strikinglycdn.com/files/87cd44b4-3830-4006-b9e1-d0a40dbeafcc/79044790185.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=resident%20evil%204%20ps2%20manual
- https://uploads.strikinglycdn.com/files/f83e0226-83bb-4ba5-a83b-8a24415f55ca/EPF_odstpenie_na_50.pdf
- https://uploads.strikinglycdn.com/files/87cd44b4-3830-4006-b9e1-d0a40dbeafcc/79044790185.pdf
- https://uploads.strikinglycdn.com/files/4fa7ca18-67ec-4ff1-9fdf-bc36e5a220fe/nisevevadupagose.pdf
- https://uploads.strikinglycdn.com/files/0ccdfdf9-719d-4d2e-af33-82aee043e9b8/92750657980.pdf
- https://uploads.strikinglycdn.com/files/66241321-db4a-4808-bb1b-5d45b87ad332/rupof.pdf
- https://uploads.strikinglycdn.com/files/8dbc0b22-ed0d-49b1-abfe-ad2c83c662fe/80889332464.pdf
- https://uploads.strikinglycdn.com/files/b43af458-68ed-4d31-a244-391ed4cc47ba/newozat.pdf
- https://cdn.shopify.com/s/files/1/0428/8118/8003/files/35588555152.pdf
- https://cdn.shopify.com/s/files/1/0502/3943/9032/files/apc_ups_es_550_user_manual.pdf
- https://cdn.shopify.com/s/files/1/0485/2645/9035/files/11315467004.pdf
- https://cdn.shopify.com/s/files/1/0498/7853/2251/files/behaviorism_and_constructivism_difference.pdf
- https://cdn.shopify.com/s/files/1/0504/7992/3365/files/xvideostudio.video_editor_apk20_download.pdf
- https://uploads.strikinglycdn.com/files/4be74b9f-00ee-4720-8235-c96b926b7958/tcp_ip_networking_interview_questions_and_answers.pdf
- https://uploads.strikinglycdn.com/files/c4e52a75-4947-404d-919b-e9a18df5ea15/78807782930.pdf
- https://uploads.strikinglycdn.com/files/71d74bc8-a342-4967-b3ea-d0230e7be83b/juvusulikirapavi.pdf
- https://uploads.strikinglycdn.com/files/428c0042-a6a9-4df1-86c4-fc6dd62668a7/vefowuluzaxitenokegakama.pdf
- https://cdn.shopify.com/s/files/1/0434/4853/3144/files/92183463211.pdf
- https://cdn.shopify.com/s/files/1/0496/6976/7321/files/tv_guide_apk_2.0.12.pdf
- https://cdn.shopify.com/s/files/1/0488/2392/6949/files/android_studio_kotlin_clear_edittext.pdf
- https://cdn.shopify.com/s/files/1/0484/0878/9150/files/expository_worksheets_3rd_grade.pdf
- https://cdn.shopify.com/s/files/1/0430/6989/8909/files/iomega_external_hard_drive_ldhd-up.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report