SUSPICIOUS — nagaxoke.pdf
SUSPICIOUS — nagaxoke.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
682db526661aa6e1241df6962419572bcd2cbc089b4fde243b5dec2cffc13b3c - SHA-1:
8a12d696febf00257aca1d7c8bb7b0fb2f6bf350 - MD5:
749928e68ffc0a30e473aee920fabfc3 - ssdeep:
768:TgGzpD0LuPfLwiVUu33HvOLs1JRRr4i2LeN2b9bFIjrLoHAToGxDtvO:sGFAfu33PmsnD2L7p4+o3DtvO - TLSH:
T1C133AEF76153EE8C7E83AB03AEAB24591149C7492132C3B418887B3DC4BC7BD6E44961 - Submitted as: nagaxoke.pdf
- File type: pdf · Size: 47889 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=define%20keratosis%20obturans, https://cdn-cms.f-static.net/uploads/4445889/normal_5f9dae8961624.pdf, https://uploads.strikinglycdn.com/files/666cd9a9-0a36-4b8d-88d6-6f8863230226/tamidurovabusisew.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=define%20keratosis%20obturans
- https://cdn-cms.f-static.net/uploads/4445889/normal_5f9dae8961624.pdf
- https://uploads.strikinglycdn.com/files/666cd9a9-0a36-4b8d-88d6-6f8863230226/tamidurovabusisew.pdf
- https://cdn.shopify.com/s/files/1/0430/9313/1425/files/knives_out_mod_apk_1.205.pdf
- https://cdn-cms.f-static.net/uploads/4375894/normal_5f8bed85ac347.pdf
- https://rimosuvifakub.weebly.com/uploads/1/3/4/3/134310068/jodez_sapekomefixunup_luzupax.pdf
- https://uploads.strikinglycdn.com/files/98cbc45d-7535-426b-9a6e-d09cf54227c2/dudotanit.pdf
- https://cdn-cms.f-static.net/uploads/4418401/normal_5f979d99bfda4.pdf
- https://risenezapaf.weebly.com/uploads/1/3/4/4/134481661/fuzudoderuvan.pdf
- https://uploads.strikinglycdn.com/files/f797d81f-220f-4e83-be92-9356b128e6af/82196585730.pdf
- https://uploads.strikinglycdn.com/files/f46ef631-1299-4e6f-9643-5902467ead40/jozakapadosi.pdf
- https://uploads.strikinglycdn.com/files/4b22be92-b83e-45f8-8dd4-a1ee89f0cc5e/wotajalikajaxin.pdf
- https://cdn-cms.f-static.net/uploads/4369318/normal_5f88d7f466707.pdf
- https://uploads.strikinglycdn.com/files/b250dff9-5024-4551-938a-6a60357a90c1/15476656237.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- cdn.shopify.com
- rimosuvifakub.weebly.com
- risenezapaf.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report