SUSPICIOUS — nigapovuse.pdf
SUSPICIOUS — nigapovuse.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
6133c3e30ee26523000dbb78188dc89ab82ff623d8a3aaf5d0915f6ab13c0ec4 - SHA-1:
a6ea8e90e079d0fdab4b51658f6087b09c4733fd - MD5:
75f5108fb3af2aee26d72465aa463dac - ssdeep:
768:mgGzpD385eevyojnagCzTcExBLkaYSWWTY9FjHr:zGFDwnXkTcaB9NzTY9FjHr - TLSH:
T1152F8DF714C7EE4C7A86AB03AEAB1056514AC7C86236EA64488C376CD47C5FDAE10670 - Submitted as: nigapovuse.pdf
- File type: pdf · Size: 35073 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/109b056b-72fe-4788-87f8-300d098731df/gujaw.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=assertion+and+reasoning+questions+biology+pdf+free+download, https://uploads.strikinglycdn.com/files/109b056b-72fe-4788-87f8-300d098731df/gujaw.pdf, https://uploads.strikinglycdn.com/files/7eb995e6-9cbe-41eb-8aef-8cfe7740eac3/naweribug.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=assertion+and+reasoning+questions+biology+pdf+free+download
- https://uploads.strikinglycdn.com/files/109b056b-72fe-4788-87f8-300d098731df/gujaw.pdf
- https://uploads.strikinglycdn.com/files/7eb995e6-9cbe-41eb-8aef-8cfe7740eac3/naweribug.pdf
- https://uploads.strikinglycdn.com/files/2969b040-c6c6-4563-81a9-f679f1dc4f23/fetum.pdf
- https://uploads.strikinglycdn.com/files/8290fc1a-ea7c-4d78-b08b-c31c21505967/91575288617.pdf
- https://uploads.strikinglycdn.com/files/c5c79f5a-5ea8-4b15-8865-d900b43c75cf/76386248785.pdf
- https://uploads.strikinglycdn.com/files/5810c2c6-73c3-4cad-b6bc-bd4b594a54f8/zabapexesumutal.pdf
- https://uploads.strikinglycdn.com/files/589f5547-6696-483c-8f48-0918617c3c32/raroxoni.pdf
- https://uploads.strikinglycdn.com/files/76241c91-d4c0-4f8c-b10d-c795796625b9/28899421322.pdf
- https://uploads.strikinglycdn.com/files/41bb71d6-ad54-4f98-8d8a-1edd8d3a4609/rumepanojizazemik.pdf
- https://uploads.strikinglycdn.com/files/25171366-88ef-4b20-b66f-5b5917cf8443/kegida.pdf
- https://cdn.shopify.com/s/files/1/0437/4514/9079/files/samsung_galaxy_tab_a_8.0_sm-t350_review.pdf
- https://cdn.shopify.com/s/files/1/0481/1826/8053/files/snapper_self_propelled_lawn_mower_walmart.pdf
- https://cdn.shopify.com/s/files/1/0431/2373/6725/files/polo_ridge_elementary_principal.pdf
- https://cdn.shopify.com/s/files/1/0434/5842/9089/files/taxifadawewo.pdf
- https://cdn.shopify.com/s/files/1/0492/3886/8124/files/basil_of_baker_street.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report