SUSPICIOUS — nudakerorupomoku.pdf
SUSPICIOUS — nudakerorupomoku.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
3110a7f05eb2b996b3d42fdde0e02b0710d2097813a87bbf569d17b3eb4923cb - SHA-1:
549e55fa7fb26a5fbda86c050e86bc859a8f0a23 - MD5:
7ca14728ee38a1d7abcd4a5b05c5dc24 - ssdeep:
768:CgGzpDGmhQVs6495yi1+WNwpO7rMJc3kU7tUaP54AZ4r9iwBP7:fGFyC/yi8p+3k8tUhGls7 - TLSH:
T19732BFF36067DC8C2BCEFB075AAA00495186DA4E6277A3A454DD3A6CD17C6FC9E40930 - Submitted as: nudakerorupomoku.pdf
- File type: pdf · Size: 43337 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=kitab+suci+agama+yahudi+pdf, https://site-1037114.mozfiles.com/files/1037114/fesudotonunesigidumatenot.pdf, https://site-1036850.mozfiles.com/files/1036850/bozofijikusogesone.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://gettraff.ru/strik?keyword=kitab+suci+agama+yahudi+pdf
- https://site-1037114.mozfiles.com/files/1037114/fesudotonunesigidumatenot.pdf
- https://site-1036850.mozfiles.com/files/1036850/bozofijikusogesone.pdf
- https://site-1036879.mozfiles.com/files/1036879/zijijosoku.pdf
- https://site-1036868.mozfiles.com/files/1036868/toregatabetibonegalaponij.pdf
- https://site-1036696.mozfiles.com/files/1036696/56441061693.pdf
- https://site-1036939.mozfiles.com/files/1036939/luzivixudinasifokigug.pdf
- https://site-1036862.mozfiles.com/files/1036862/lekadegil.pdf
- https://uploads.strikinglycdn.com/files/3166316e-bb4d-4fd9-b3ce-de76639783de/40194017340.pdf
- https://uploads.strikinglycdn.com/files/c03c9af1-8d4e-43cc-9c03-91f8aa363995/wuratagob.pdf
- http://morodav.dogeatdog.ca/uploads/1/3/0/7/130739560/2555786.pdf
- http://funijugoj.wheatco.org/uploads/1/3/0/8/130874284/noxeguze.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037114.mozfiles.com
- site-1036850.mozfiles.com
- site-1036879.mozfiles.com
- site-1036868.mozfiles.com
- site-1036696.mozfiles.com
- site-1036939.mozfiles.com
- site-1036862.mozfiles.com
- uploads.strikinglycdn.com
- morodav.dogeatdog.ca
- funijugoj.wheatco.org
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report