SUSPICIOUS — beregolonorufa.pdf
SUSPICIOUS — beregolonorufa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
42c393417434974b76433b0cbed2d7bb716dbc60a54b207f2a1ba7fa11ecb913 - SHA-1:
80a76c20efd8c7f657b3edf05a739d9b53c41681 - MD5:
e5d753e303dfa7c0144e108bfa0df34e - ssdeep:
1536:SGFEp61/l+KHbVAuZA0m0toBQQy3JENOKj6Cs1ySgU:LFEQ1thHiAuB5y3pKmCs1ln - TLSH:
T13B35CFF310A7ED8C3E96AB07ADA61569104AC7CA7277D36054C83BBDC4785FCAE10820 - Submitted as: beregolonorufa.pdf
- File type: pdf · Size: 58763 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=iron+man+parents+guide, https://uploads.strikinglycdn.com/files/5d72d517-077d-48fe-8789-32b803f942c9/wukogumos.pdf, https://uploads.strikinglycdn.com/files/be702f00-5095-4472-9937-6bf611c6735a/wavugoxiniwululijed.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=iron+man+parents+guide
- https://uploads.strikinglycdn.com/files/5d72d517-077d-48fe-8789-32b803f942c9/wukogumos.pdf
- https://uploads.strikinglycdn.com/files/be702f00-5095-4472-9937-6bf611c6735a/wavugoxiniwululijed.pdf
- https://uploads.strikinglycdn.com/files/1fa856c2-b8c2-45c4-98a0-896ce208aa24/loviridarirideduzuxok.pdf
- https://site-1040879.mozfiles.com/files/1040879/55753365944.pdf
- https://site-1036991.mozfiles.com/files/1036991/76046707621.pdf
- https://site-1043119.mozfiles.com/files/1043119/32802128192.pdf
- https://site-1037222.mozfiles.com/files/1037222/fugaza.pdf
- https://site-1042672.mozfiles.com/files/1042672/wujivawu.pdf
- https://site-1042348.mozfiles.com/files/1042348/zimufomosekogupu.pdf
- https://site-1036971.mozfiles.com/files/1036971/88297178525.pdf
- https://site-1040129.mozfiles.com/files/1040129/kowenedonamitovefomituvos.pdf
- https://uploads.strikinglycdn.com/files/9997770b-0825-47d6-8b08-49aad8a8e7f9/84045644008.pdf
- https://uploads.strikinglycdn.com/files/032393cd-69b4-4fbc-847c-ae0d0c889fe7/ririvofuwomibugomukiwuwar.pdf
- https://uploads.strikinglycdn.com/files/67d0460f-5a4e-48e4-beb6-172e6d0d129f/rasujamobukopef.pdf
- https://uploads.strikinglycdn.com/files/b2d11908-36df-4c6b-bd72-9c1cb5df48e6/jemumizozavavozaku.pdf
- https://uploads.strikinglycdn.com/files/010b1cf4-a770-4bf3-b22a-efb0fd83d8a8/redagonolux.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- site-1040879.mozfiles.com
- site-1036991.mozfiles.com
- site-1043119.mozfiles.com
- site-1037222.mozfiles.com
- site-1042672.mozfiles.com
- site-1042348.mozfiles.com
- site-1036971.mozfiles.com
- site-1040129.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report