SUSPICIOUS — ferudimafuserunomilitas.pdf
SUSPICIOUS — ferudimafuserunomilitas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4af0d2721fb1866de404cb9b94c503c257f39e694dea37236a9f32916b9b01ea - SHA-1:
37bf28a56fdc28f4023a5c5f416252374c7f17a7 - MD5:
60f45f910bf644f1d9272826c9b0e4c7 - ssdeep:
1536:WGF7bI6Ff1/Iyti+/wksAIRbMXpnNRTHWBvi7oczLs:vF7s6cyttwGQGnNRTQnP - TLSH:
T14A34BEF340E3DCCCBE87AB479DAB04656145C78C21369BA0459D7B2DD5BC6BDAE20820 - Submitted as: ferudimafuserunomilitas.pdf
- File type: pdf · Size: 56701 bytes
- Verdict: suspicious (58/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/74596741-0e30-4a4e-916f-cc3a2c77d2f1/vigodagukenabematalop.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=kirchhoff%2527+s+current+law+pdf, https://site-1036981.mozfiles.com/files/1036981/nuperelirax.pdf, https://site-1036685.mozfiles.com/files/1036685/69778368637.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=kirchhoff%2527+s+current+law+pdf
- https://site-1036981.mozfiles.com/files/1036981/nuperelirax.pdf
- https://site-1036685.mozfiles.com/files/1036685/69778368637.pdf
- https://site-1037071.mozfiles.com/files/1037071/52670912363.pdf
- https://site-1036719.mozfiles.com/files/1036719/96774720954.pdf
- https://site-1036925.mozfiles.com/files/1036925/xoxobomagiriwox.pdf
- https://uploads.strikinglycdn.com/files/0c3531f9-0de7-4db2-98ac-8c3755f5a4ce/remidukonumugux.pdf
- https://uploads.strikinglycdn.com/files/74596741-0e30-4a4e-916f-cc3a2c77d2f1/vigodagukenabematalop.pdf
- https://uploads.strikinglycdn.com/files/35b6883f-ef0d-49c4-b27a-665e4227ab18/62172458968.pdf
- https://uploads.strikinglycdn.com/files/02d0e3b7-58c9-460d-b822-04564e4422f5/rovikubumepilu.pdf
- https://uploads.strikinglycdn.com/files/5afe974f-1638-48bd-9a0e-84c1b42c1013/65535795763.pdf
- https://site-1036876.mozfiles.com/files/1036876/rerodadutoxemesafosisida.pdf
- https://site-1037091.mozfiles.com/files/1037091/gorugepujogupi.pdf
- https://site-1037129.mozfiles.com/files/1037129/98179000566.pdf
- https://site-1036691.mozfiles.com/files/1036691/vijiriki.pdf
- http://files.greenfieldcharge.org/uploads/1/3/1/4/131406082/rozibumulagexuva.pdf
- http://files.tjeffersoncarey.com/uploads/1/3/0/7/130775304/3104249.pdf
- http://files.makwawamalawi.com/uploads/1/3/2/7/132740860/zuder.pdf
- http://likum.chathletics.org/uploads/1/3/1/8/131857631/sabepogakugasumudax.pdf
- http://xebedaj.briargacrew.com/uploads/1/3/1/4/131453526/vudukajezejoluzuba.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- gettraff.ru
- site-1036981.mozfiles.com
- site-1036685.mozfiles.com
- site-1037071.mozfiles.com
- site-1036719.mozfiles.com
- site-1036925.mozfiles.com
- uploads.strikinglycdn.com
- site-1036876.mozfiles.com
- site-1037091.mozfiles.com
- site-1037129.mozfiles.com
- site-1036691.mozfiles.com
- files.greenfieldcharge.org
- files.tjeffersoncarey.com
- files.makwawamalawi.com
- likum.chathletics.org
- xebedaj.briargacrew.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report