SUSPICIOUS — nuburi.pdf
SUSPICIOUS — nuburi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 53 detection engines flagged it.
Identification
- SHA-256:
56d42258f9750bf2e1034a64bbd80ad76ccdf1566f7222b4bc92b4f072e7fd9d - SHA-1:
a54baea01c63afa3ee87814476994484a325894b - MD5:
5ee16d03a82faedcfa7ebb7c5441a32b - ssdeep:
768:egGzpDvBTOghfPgSLNtw3ED4zqVYquHuidQCkSks+awtOnIZ+:bGFjr5twUTOvdhk+IOnIZ+ - TLSH:
T158329DF354ABCD8C7E8AAB039DE614995189CB4C2236DB60158D7B3DD4BC3BD6E00851 - Submitted as: nuburi.pdf
- File type: pdf · Size: 45465 bytes
- Verdict: suspicious (44/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=wood+gun+rack+plans+pdf, https://uploads.strikinglycdn.com/files/5e79bd69-bcc5-40cf-8396-da773cadfa1b/87875585110.pdf, https://uploads.strikinglycdn.com/files/1a59a5a2-3838-4b1b-8534-d8091e051e92/59423443846.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=wood+gun+rack+plans+pdf
- https://uploads.strikinglycdn.com/files/5e79bd69-bcc5-40cf-8396-da773cadfa1b/87875585110.pdf
- https://uploads.strikinglycdn.com/files/1a59a5a2-3838-4b1b-8534-d8091e051e92/59423443846.pdf
- https://uploads.strikinglycdn.com/files/1966672e-9283-4893-8e05-b01f7d15c3a6/nosadeziwelawas.pdf
- https://uploads.strikinglycdn.com/files/916224cf-f40d-4560-adb0-7e7c1a465eba/41453913594.pdf
- https://uploads.strikinglycdn.com/files/d8d2177e-579a-4b35-8286-4712b732789e/17811969397.pdf
- https://uploads.strikinglycdn.com/files/63cc96d1-e9da-4a59-9fdb-3aa265630ae6/bibebafufikofaxud.pdf
- https://uploads.strikinglycdn.com/files/3e5bd369-6017-4d8f-9ea0-a714e2c68bdf/mejafokuvegurukazisolugu.pdf
- https://uploads.strikinglycdn.com/files/4f0c0d9c-4c5b-4982-83bc-7d1978eb0a15/83548277881.pdf
- https://uploads.strikinglycdn.com/files/a83497ea-ccb4-4b10-9185-9dad35c7d7c8/58582190870.pdf
- http://vokij.lilymariecreative.com/uploads/1/3/0/7/130775705/dawezironaruxulowow.pdf
- http://files.hbscooters.com/uploads/1/3/1/3/131378776/7020496.pdf
- http://gorivif.eriepetemergency.com/uploads/1/3/1/0/131070874/dunibasojuk.pdf
- http://files.soupsatthestation.com/uploads/1/3/0/9/130969065/pisodewa-dabovifafekazo-wijet-foxekiwu.pdf
- https://uploads.strikinglycdn.com/files/d4717992-e00a-47a5-9039-2556a578a6c8/zabojarupogasijir.pdf
- https://uploads.strikinglycdn.com/files/762c5e73-8769-4074-ba20-c372d9df3ad4/10815788473.pdf
- https://uploads.strikinglycdn.com/files/d1c253cd-b079-4fab-bcd2-d1ea314cf1bc/judodapajubanarefeteraf.pdf
- https://uploads.strikinglycdn.com/files/c47e5dcc-9e23-41e9-a890-b22b81513a76/10920661571.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- vokij.lilymariecreative.com
- files.hbscooters.com
- gorivif.eriepetemergency.com
- files.soupsatthestation.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report