SUSPICIOUS — kusebo.pdf
SUSPICIOUS — kusebo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
f7f3a1f50b87ba24b421cd8be262620de24cfad9185fce1af8fed7035af82a6d - SHA-1:
0c10b8725038f36187c1848d758ff86e858dbd04 - MD5:
8fdfc42a359c4a229c645de39c3d06e0 - ssdeep:
768:dgGzpDdXq1wEecBJj3lXH3GlZSXh9y2bMufm:eGFRcplXC4R9y24ufm - TLSH:
T1402F7DF71063EC4CB78AAB076EAA1458614AD38E613397A015987B6CD0BC6FC7F11631 - Submitted as: kusebo.pdf
- File type: pdf · Size: 35345 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=the+western+heritage+since+1300+ap+e, https://site-1036667.mozfiles.com/files/1036667/juvagebenupu.pdf, https://site-1037184.mozfiles.com/files/1037184/womigokolu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=the+western+heritage+since+1300+ap+e
- https://site-1036667.mozfiles.com/files/1036667/juvagebenupu.pdf
- https://site-1037184.mozfiles.com/files/1037184/womigokolu.pdf
- https://site-1038345.mozfiles.com/files/1038345/24955694498.pdf
- https://site-1039217.mozfiles.com/files/1039217/56037220531.pdf
- https://site-1040299.mozfiles.com/files/1040299/5991682262.pdf
- https://site-1038414.mozfiles.com/files/1038414/rojixipetazakupomak.pdf
- https://site-1036783.mozfiles.com/files/1036783/20267632201.pdf
- https://site-1043094.mozfiles.com/files/1043094/vovexewat.pdf
- http://mipebilad.studentfoundations.com/uploads/1/3/1/4/131407089/8713933.pdf
- http://zometab.vintage3djoes.com/uploads/1/3/2/6/132680921/mowezewosejovu.pdf
- https://site-1037856.mozfiles.com/files/1037856/pumegud.pdf
- https://site-1036671.mozfiles.com/files/1036671/xusotizutelubuguzos.pdf
- https://site-1037028.mozfiles.com/files/1037028/75652594580.pdf
- https://site-1039759.mozfiles.com/files/1039759/64643729791.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036667.mozfiles.com
- site-1037184.mozfiles.com
- site-1038345.mozfiles.com
- site-1039217.mozfiles.com
- site-1040299.mozfiles.com
- site-1038414.mozfiles.com
- site-1036783.mozfiles.com
- site-1043094.mozfiles.com
- mipebilad.studentfoundations.com
- zometab.vintage3djoes.com
- site-1037856.mozfiles.com
- site-1036671.mozfiles.com
- site-1037028.mozfiles.com
- site-1039759.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report