SUSPICIOUS — nurudufewi_kimul_givokon_sovun.pdf
SUSPICIOUS — nurudufewi_kimul_givokon_sovun.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
36ad4632705083ad27d0564c0b207e6a3f10c7e2fa4b02a9b9402f8ec8e28950 - SHA-1:
e7ad30fec98c966da4912e91d05798fc51b43df7 - MD5:
f86c47b59059efc8dec109512ed5078c - ssdeep:
768:SWgGzpDnpQx4KtJaMnBaYy4IAavuhjZ/MR3ifhpJ4EzqkAFN69SNC:UGFzpww9V2h9UR3ehpzzqz69SNC - TLSH:
T1BA329CF714D7DC8CBA8A9B43ADA72568118DD3886232DBA048C87B1DD4BC27D7F11860 - Submitted as: nurudufewi_kimul_givokon_sovun.pdf
- File type: pdf · Size: 45016 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=aeronautical%20information%20publication, https://site-1038602.mozfiles.com/files/1038602/lanitobutarix.pdf, https://site-1043174.mozfiles.com/files/1043174/59690501037.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=aeronautical%20information%20publication
- https://site-1038602.mozfiles.com/files/1038602/lanitobutarix.pdf
- https://site-1043174.mozfiles.com/files/1043174/59690501037.pdf
- https://site-1036756.mozfiles.com/files/1036756/87130328580.pdf
- https://site-1042765.mozfiles.com/files/1042765/3903394654.pdf
- https://uploads.strikinglycdn.com/files/e4fed3b0-0aef-4381-a071-5e99642fb408/burapiwaletudorezap.pdf
- https://uploads.strikinglycdn.com/files/4cc13e88-ded5-45f3-9792-5d9033d13350/64008422007.pdf
- https://uploads.strikinglycdn.com/files/59ed505e-b28d-4813-8027-97558228b356/14859351629.pdf
- https://uploads.strikinglycdn.com/files/dd26a3d0-0bd5-4513-aace-05d7c1a36d60/gobapararalafoxajepo.pdf
- https://uploads.strikinglycdn.com/files/d7c27b86-dbe3-4e3e-b1d4-3f557434fa8f/semavepatebi.pdf
- https://bewupoterefi.weebly.com/uploads/1/3/1/3/131380107/wizaba.pdf
- https://remewizefo.weebly.com/uploads/1/3/1/8/131856163/dilujekup.pdf
- https://vuxilimibipemop.weebly.com/uploads/1/3/1/4/131453056/fufirasabareguxil.pdf
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/voranipekaloxuw.pdf
- https://vimiwegom.weebly.com/uploads/1/3/0/7/130775837/mefujunokota-xojiv.pdf
- https://uploads.strikinglycdn.com/files/34d1d6b4-0109-49e5-9f51-35e3557f03bd/vuwozuwe.pdf
- https://uploads.strikinglycdn.com/files/02b5fc7b-64f9-4cb3-a678-75a9ca5a6223/28096107097.pdf
- https://uploads.strikinglycdn.com/files/d81c8c1f-63df-46b0-9d18-2603343aca00/wibosizuroka.pdf
- https://uploads.strikinglycdn.com/files/ed5df2ef-1052-4a1a-a4a2-a6caff4c72cd/60945389507.pdf
- https://uploads.strikinglycdn.com/files/e0a655fd-73b4-4fb1-9916-b7edb667f3a4/74492670555.pdf
- https://uploads.strikinglycdn.com/files/cd0c09e4-43bd-403f-828b-cfece807ae71/kutenenaximonomufuseluju.pdf
- https://uploads.strikinglycdn.com/files/e8f2ef78-da66-40b4-9b1d-6cb1afbd92a7/rijagifefodo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- site-1038602.mozfiles.com
- site-1043174.mozfiles.com
- site-1036756.mozfiles.com
- site-1042765.mozfiles.com
- uploads.strikinglycdn.com
- bewupoterefi.weebly.com
- remewizefo.weebly.com
- vuxilimibipemop.weebly.com
- vilukenuxe.weebly.com
- vimiwegom.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report