SUSPICIOUS — kulosox.pdf
SUSPICIOUS — kulosox.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
3c42d6faf51041dc1706f12f300515a66051c7f816e58b845f7676f045a18ba5 - SHA-1:
70bea0c98fd137c1a145cfaa282973ebddc88231 - MD5:
23215e571d890d563dac693c31adf5cb - ssdeep:
768:WgGzpDWpkHmnF5kpbeTfvIMIG5wzoKf0y6jIKbTWdoJe:DGFypkmkmHRIeyfKzTMoJe - TLSH:
T122307CF350ABED8C7A87AB036DEA11586089C38C7127D75059C8376DD4BCABDBE00921 - Submitted as: kulosox.pdf
- File type: pdf · Size: 35830 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=devdas%20free%20online%20streaming, https://site-1038649.mozfiles.com/files/1038649/71500017766.pdf, https://site-1042277.mozfiles.com/files/1042277/nigegakesivagarubulosefu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=devdas%20free%20online%20streaming
- https://site-1038649.mozfiles.com/files/1038649/71500017766.pdf
- https://site-1042277.mozfiles.com/files/1042277/nigegakesivagarubulosefu.pdf
- https://site-1040618.mozfiles.com/files/1040618/pikutugu.pdf
- https://uploads.strikinglycdn.com/files/8d443d12-1fed-4997-a15d-1c7e0ca4fd1e/fajig.pdf
- https://uploads.strikinglycdn.com/files/e072f449-12e8-4ef4-9adc-2da18ac624c7/kowepejofiroxejo.pdf
- https://uploads.strikinglycdn.com/files/9341d225-b4f7-4f07-a923-1c275063fb2c/7906344021.pdf
- https://uploads.strikinglycdn.com/files/40c01af4-d448-44d2-bfd5-bf87b4a4d4c9/tavuvovojobagowopes.pdf
- https://uploads.strikinglycdn.com/files/3e4310e5-15a1-4669-900a-954ab2040919/97435257164.pdf
- https://uploads.strikinglycdn.com/files/e5fe7ed7-3688-4baa-94d7-8246fc852e76/rugebupobesobetenifor.pdf
- https://uploads.strikinglycdn.com/files/9e5d37e1-36f4-4e0b-9d16-d1d5d9cc9132/fopajowinularanebexe.pdf
- https://site-1043314.mozfiles.com/files/1043314/tuxedakape.pdf
- https://site-1036930.mozfiles.com/files/1036930/5244873923.pdf
- https://site-1039180.mozfiles.com/files/1039180/73503755159.pdf
- https://site-1041091.mozfiles.com/files/1041091/zowanamiludosavusopala.pdf
- https://site-1037061.mozfiles.com/files/1037061/68790952188.pdf
- https://site-1048260.mozfiles.com/files/1048260/pexos.pdf
- https://site-1040101.mozfiles.com/files/1040101/fopekuwu.pdf
- https://site-1043908.mozfiles.com/files/1043908/88618499447.pdf
- https://site-1043328.mozfiles.com/files/1043328/34039587261.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- site-1038649.mozfiles.com
- site-1042277.mozfiles.com
- site-1040618.mozfiles.com
- uploads.strikinglycdn.com
- site-1043314.mozfiles.com
- site-1036930.mozfiles.com
- site-1039180.mozfiles.com
- site-1041091.mozfiles.com
- site-1037061.mozfiles.com
- site-1048260.mozfiles.com
- site-1040101.mozfiles.com
- site-1043908.mozfiles.com
- site-1043328.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report