SUSPICIOUS — nojof.pdf
SUSPICIOUS — nojof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
522c1099b7562c0962defbccfc439a8daf59005efeaf52bb13c27b8115c2c826 - SHA-1:
7d7fbc702749ae575e398569fcbe2f9e775d4456 - MD5:
b085a69e1b78d838d4e86fd56bfd78c7 - ssdeep:
1536:NGFrpqbdRP6wSHFsvh2FVIAMrkOusjG3sTpD:QFrpqHPVSlsv+CY7sS3s1 - TLSH:
T1EF34AEB35087DC4CB9CBAB43ADAA106D7056D3C93172A69415CC3B7CD478AFD6E20A60 - Submitted as: nojof.pdf
- File type: pdf · Size: 54080 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6cc9ce28-6dd7-4eb1-9da2-7410603cec95/58350949518.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=kundrathile%20kumaranukku%20kondattam%20mp, https://site-1037854.mozfiles.com/files/1037854/fivedevidizivemal.pdf, https://site-1039301.mozfiles.com/files/1039301/bilanalegofu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=kundrathile%20kumaranukku%20kondattam%20mp
- https://site-1037854.mozfiles.com/files/1037854/fivedevidizivemal.pdf
- https://site-1039301.mozfiles.com/files/1039301/bilanalegofu.pdf
- https://site-1041846.mozfiles.com/files/1041846/36384800969.pdf
- https://site-1039259.mozfiles.com/files/1039259/60022796731.pdf
- https://site-1039950.mozfiles.com/files/1039950/50182540156.pdf
- https://uploads.strikinglycdn.com/files/6cc9ce28-6dd7-4eb1-9da2-7410603cec95/58350949518.pdf
- https://uploads.strikinglycdn.com/files/dd1f63a9-6133-4da9-856a-0040cd58a25c/takuguwokavin.pdf
- https://uploads.strikinglycdn.com/files/6123b38d-ef87-4e4b-bb44-01dd515c5a75/83255258201.pdf
- https://uploads.strikinglycdn.com/files/dccb7a9e-1a6d-4371-b0f3-5664d29bde25/62742234193.pdf
- https://uploads.strikinglycdn.com/files/55e6bc68-65fb-469b-89e0-cdeb9c7b840b/ripetajurozudanodirazome.pdf
- https://uploads.strikinglycdn.com/files/55965b2e-1988-40c8-933c-15e0ace4c47b/54677830084.pdf
- https://uploads.strikinglycdn.com/files/79a33fd6-0db1-4945-b249-d44dea6dbdce/dusobexiwipaju.pdf
- https://uploads.strikinglycdn.com/files/c12465c4-47df-49d0-8a8f-418c58d2032e/99820552280.pdf
- https://uploads.strikinglycdn.com/files/0f554f85-7e54-40f9-87d5-532815b0cbfd/91941610470.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1037854.mozfiles.com
- site-1039301.mozfiles.com
- site-1041846.mozfiles.com
- site-1039259.mozfiles.com
- site-1039950.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report