SUSPICIOUS — kerilumila.pdf
SUSPICIOUS — kerilumila.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 2 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
adb462515a2fe2d2903746986cbc4276c1cbbf993edd7945710c3328c7dcd578 - SHA-1:
fb3864bc981320eb9bde61b94774206bf0a29f2e - MD5:
5ca77fad2a4ab91b7b4473372edb107c - ssdeep:
768:rgGzpD/LQVbbjaHy4UfowTyjgBc9qqIebA1dSqwXqu6GuLcI:UGFTLU7f/Bc0WA1eau6GuLcI - TLSH:
T1D8328DF71097DD9D7A8FAF079DBA1058A48AD78C612297A0508D372DC0BC6EC6F10A61 - Submitted as: kerilumila.pdf
- File type: pdf · Size: 46919 bytes
- Verdict: suspicious (58/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/6f5f81b7-db65-461a-acd4-6f3a48f8d91b/62317329020.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=sweet+potato+fritters+baby, https://site-1036955.mozfiles.com/files/1036955/mugopevaroxogojetixaruwes.pdf, https://site-1038475.mozfiles.com/files/1038475/33167871731.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=sweet+potato+fritters+baby
- https://site-1036955.mozfiles.com/files/1036955/mugopevaroxogojetixaruwes.pdf
- https://site-1038475.mozfiles.com/files/1038475/33167871731.pdf
- https://site-1036764.mozfiles.com/files/1036764/zipimositijozaze.pdf
- https://site-1036746.mozfiles.com/files/1036746/sudowawosej.pdf
- https://site-1039356.mozfiles.com/files/1039356/53465553716.pdf
- https://uploads.strikinglycdn.com/files/6f5f81b7-db65-461a-acd4-6f3a48f8d91b/62317329020.pdf
- https://uploads.strikinglycdn.com/files/9fc9c64b-9597-46d8-9c87-d5695dc66eeb/silatizobimaranurowisivi.pdf
- https://uploads.strikinglycdn.com/files/15b286ff-6fc9-47b1-8c08-45aeba24bfa4/92701875807.pdf
- https://uploads.strikinglycdn.com/files/77bdbe6f-8a81-4b45-9588-a5d2784e8917/41960034624.pdf
- https://uploads.strikinglycdn.com/files/385cda86-e481-4a47-8237-64e525c652ce/65565541445.pdf
- https://uploads.strikinglycdn.com/files/80075f22-14b6-491e-a437-b4fb7a83ba85/45597848850.pdf
- https://uploads.strikinglycdn.com/files/4230882c-91b9-40a8-873c-a6c1ad487b2e/lijadofupugesagiv.pdf
- https://uploads.strikinglycdn.com/files/150588c6-d865-4f2d-996c-a42c4ff414b7/ridetowodurevemiri.pdf
- https://uploads.strikinglycdn.com/files/82500919-37d8-4be5-aac4-ffb59fb81166/munatawosurovenomapebe.pdf
- https://uploads.strikinglycdn.com/files/6153a1d9-ecfd-4c7e-ad92-5af5c623d779/49751033917.pdf
- https://uploads.strikinglycdn.com/files/771afd78-a017-45e9-bf5e-2c508c877ae1/selupubemataxubobif.pdf
- https://uploads.strikinglycdn.com/files/d0d05c6a-4876-4fdd-a839-172cdea8a639/53378655778.pdf
- https://uploads.strikinglycdn.com/files/bb103b6e-eefc-465c-92d1-3d74064a87f1/xatoxakusamaveju.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- site-1036955.mozfiles.com
- site-1038475.mozfiles.com
- site-1036764.mozfiles.com
- site-1036746.mozfiles.com
- site-1039356.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report