SUSPICIOUS — kilal.pdf
SUSPICIOUS — kilal.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9420a25e4f77deb7da7dcdf86cecbfc1eeeadf845f5e903dd9a9c7f900af47d0 - SHA-1:
e947867516c88fb274b78bb0257e12c4a7d855fe - MD5:
2bb8f1fec3f2c509f8d08e0a23a0fce4 - ssdeep:
768:xgGzpDK340HdKBQF9r4sFOkaGzVLoNqhXbdDQedoQvu:CGF23NKSFx4snZXbdD9aQvu - TLSH:
T119319FF350B7EC9CB68AAF033EB61449540AC74D5032D6B049C97A2DC8B86FC6E54E61 - Submitted as: kilal.pdf
- File type: pdf · Size: 41518 bytes
- Verdict: suspicious (58/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/83734682-4458-4c63-9310-d1048e857bff/3318317317.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=school+supplies+pictures+pdf, https://site-1036951.mozfiles.com/files/1036951/latugumajotafilu.pdf, https://site-1036798.mozfiles.com/files/1036798/19401290974.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=school+supplies+pictures+pdf
- https://site-1036951.mozfiles.com/files/1036951/latugumajotafilu.pdf
- https://site-1036798.mozfiles.com/files/1036798/19401290974.pdf
- https://site-1037870.mozfiles.com/files/1037870/fuxumik.pdf
- https://site-1037149.mozfiles.com/files/1037149/82765487719.pdf
- https://cdn.shopify.com/s/files/1/0438/7949/7896/files/vorasedoretewuxe.pdf
- https://uploads.strikinglycdn.com/files/83734682-4458-4c63-9310-d1048e857bff/3318317317.pdf
- https://uploads.strikinglycdn.com/files/c2a3fc71-9820-4630-a18a-97991536f19c/mexonigovuli.pdf
- https://uploads.strikinglycdn.com/files/1a39aeea-aef4-49e5-acb5-6c3ce3d092dc/6099494571.pdf
- https://uploads.strikinglycdn.com/files/d6219719-0ecb-4cc2-9904-716d31992b82/defegitaxawipulefa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- site-1036951.mozfiles.com
- site-1036798.mozfiles.com
- site-1037870.mozfiles.com
- site-1037149.mozfiles.com
- cdn.shopify.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report