SUSPICIOUS — kokumon.pdf
SUSPICIOUS — kokumon.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
e41ad4bf51fc75bd705bcf02536256523cc4103d2835305e8b54317806f1c65a - SHA-1:
56febaa0cd55c886378a36ed1a64267c8d739c51 - MD5:
242fd9600d43fd02f4b2d25f4aba69e6 - ssdeep:
768:WgGzpDTpO2wMqBJD341iYdXmSw2iT9OT9DQ0SccSEAyGaayceu/tnoDqUwn:DGFPpNLBm12b2zXXYaJch1noDqUwn - TLSH:
T1E6328EF35097ED4C3A8B8F43ADAB159E9086D78D61279B50049C777CC8BC6AE6F00521 - Submitted as: kokumon.pdf
- File type: pdf · Size: 47364 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=the+cold+war+a+new+history+pdf, https://cdn-cms.f-static.net/uploads/4366995/normal_5f887fe679c59.pdf, https://cdn-cms.f-static.net/uploads/4370284/normal_5f8dc91b91d46.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=the+cold+war+a+new+history+pdf
- https://cdn-cms.f-static.net/uploads/4366995/normal_5f887fe679c59.pdf
- https://cdn-cms.f-static.net/uploads/4370284/normal_5f8dc91b91d46.pdf
- https://cdn-cms.f-static.net/uploads/4365657/normal_5f8a71a8d1bdc.pdf
- https://cdn-cms.f-static.net/uploads/4367921/normal_5f8dd79f8f888.pdf
- https://s3.amazonaws.com/jamokaroxoj/25917570894.pdf
- https://s3.amazonaws.com/wonoti/18799029378.pdf
- https://s3.amazonaws.com/pazifetanegapu/tetidejegaguf.pdf
- https://s3.amazonaws.com/subud/logical_and_analytical_reasoning_questions_for_class_5.pdf
- https://korodaziso.weebly.com/uploads/1/3/0/7/130740443/vesadebupute.pdf
- https://jamuseramomuf.weebly.com/uploads/1/3/1/8/131871426/666c4a.pdf
- https://sixapinipuso.weebly.com/uploads/1/3/1/3/131384402/4446223.pdf
- https://funiwulew.weebly.com/uploads/1/3/2/8/132814073/xovudavexamobe.pdf
- https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/foburadip.pdf
- https://gaxopekel.weebly.com/uploads/1/3/0/9/130969853/vufizopi.pdf
- https://xonuveviriniw.weebly.com/uploads/1/3/0/7/130738603/73179efb5.pdf
- https://sanuvexugivi.weebly.com/uploads/1/3/1/6/131606490/laguleb.pdf
- https://cdn.shopify.com/s/files/1/0432/2168/0283/files/55623576095.pdf
- https://cdn.shopify.com/s/files/1/0494/1378/3719/files/robidovegifu.pdf
- https://cdn.shopify.com/s/files/1/0266/9412/3720/files/pitch_in_music_refers_to.pdf
- https://cdn.shopify.com/s/files/1/0482/6785/3986/files/future_city_model.pdf
- https://cdn.shopify.com/s/files/1/0499/4387/1643/files/your_safety_is_our_responsibility_essay.pdf
- https://s3.amazonaws.com/jamokaroxoj/yoshiko_kawashima.pdf
- https://s3.amazonaws.com/henghuili-files/juruvatovelodakebosej.pdf
- https://s3.amazonaws.com/fasanag/49307728328.pdf
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- s3.amazonaws.com
- korodaziso.weebly.com
- jamuseramomuf.weebly.com
- sixapinipuso.weebly.com
- funiwulew.weebly.com
- xojerajap.weebly.com
- gaxopekel.weebly.com
- xonuveviriniw.weebly.com
- sanuvexugivi.weebly.com
- cdn.shopify.com
- www.w3.org
- purl.org
- bt4g.com
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report