SUSPICIOUS — kafilufewaravugevule.pdf
SUSPICIOUS — kafilufewaravugevule.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
b13be06d48404b07028c5dc6e72186290ed1810a9d232d58f8f3c756b2a6ed1b - SHA-1:
d5691f2996ceb2ca2175e55f0cf7dcc19844fdfd - MD5:
4bdbf76f65a1616fa7d36286073fe135 - ssdeep:
768:YgGzpD7pJh/QHPTZnBLQjA4hBpwCx4oViSi6hOUMcB7ZdPsfGL:1GFXtQH70bhVViFUMcB7ZdPsfGL - TLSH:
T1F832ADF300A7DE4D7A839B83ADEB50997059C3887132A26445C97B6EC87C2BC6F51960 - Submitted as: kafilufewaravugevule.pdf
- File type: pdf · Size: 45589 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=liste+suffixes+fran%25C3%25A7ais+pdf, https://uploads.strikinglycdn.com/files/cbfc317f-04c7-4363-b3a6-581fab2361e9/jibuzegukul.pdf, https://uploads.strikinglycdn.com/files/82eb8756-fb9b-4056-b92c-760319b9e676/98579579106.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=liste+suffixes+fran%25C3%25A7ais+pdf
- https://uploads.strikinglycdn.com/files/cbfc317f-04c7-4363-b3a6-581fab2361e9/jibuzegukul.pdf
- https://uploads.strikinglycdn.com/files/82eb8756-fb9b-4056-b92c-760319b9e676/98579579106.pdf
- https://uploads.strikinglycdn.com/files/6375e922-458c-49ad-a873-a4cb33df910a/ronulozisij.pdf
- https://uploads.strikinglycdn.com/files/0587ae5b-6f81-4ebd-afec-0642b8d5d9ca/leloxojumumaxonekizowo.pdf
- https://uploads.strikinglycdn.com/files/77319ddc-c67c-4c56-b23c-45ed32ae017d/wotoxesesolilu.pdf
- https://uploads.strikinglycdn.com/files/dd486fe3-4f9b-40d8-8e9e-00440c508c93/49643546671.pdf
- https://uploads.strikinglycdn.com/files/7262c2b2-7fe0-4cf4-9b4c-e28200200b89/79097300130.pdf
- https://uploads.strikinglycdn.com/files/f881bb8f-df4d-4c58-8337-5666f864387a/35951082960.pdf
- https://uploads.strikinglycdn.com/files/84c14874-984a-47d0-8aca-21c2ad16027c/butar.pdf
- https://site-1040559.mozfiles.com/files/1040559/15720020053.pdf
- https://site-1038728.mozfiles.com/files/1038728/kajak.pdf
- https://site-1042023.mozfiles.com/files/1042023/posabinuzab.pdf
- https://site-1036988.mozfiles.com/files/1036988/wapuxojap.pdf
- https://site-1037897.mozfiles.com/files/1037897/kuxusimal.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- site-1040559.mozfiles.com
- site-1038728.mozfiles.com
- site-1042023.mozfiles.com
- site-1036988.mozfiles.com
- site-1037897.mozfiles.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report