SUSPICIOUS — nier_automata_best_weapons_combo.pdf
SUSPICIOUS — nier_automata_best_weapons_combo.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 3 of 50 detection engines flagged it.
Identification
- SHA-256:
6b71ea515b23d566cb1a6fb8867446f1583a62c8e7cea42ce858a46b6e64d701 - SHA-1:
a2f23c067fe1134cde3639726a68ee44353950c7 - MD5:
ef5fc7dcb1f40d58c002bcb9631caccd - ssdeep:
1536:MGFI+1xZbQwVlEPRbr46AOSkVn0jOpH463:pFI0nbQwD6brZAONd0jIJ - TLSH:
T1DC34AEF34067CD8C3B8B6B53A9AB2159219EDB896232975105CCB72CD8BCABD7D01D10 - Submitted as: nier_automata_best_weapons_combo.pdf
- File type: pdf · Size: 56550 bytes
- Verdict: suspicious (44/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=nier+automata+best+weapons+combo, https://cdn.shopify.com/s/files/1/0437/8460/1752/files/42819487189.pdf, https://bedakowunuva.weebly.com/uploads/1/3/4/3/134342711/3130aea95da.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=nier+automata+best+weapons+combo
- https://cdn.shopify.com/s/files/1/0437/8460/1752/files/42819487189.pdf
- https://bedakowunuva.weebly.com/uploads/1/3/4/3/134342711/3130aea95da.pdf
- https://radisowe.weebly.com/uploads/1/3/4/3/134366404/d9de06967e1e87b.pdf
- https://cdn.shopify.com/s/files/1/0502/9920/7863/files/city_car_driving_simulator_apk_hack.pdf
- https://cdn.shopify.com/s/files/1/0482/3082/6141/files/pinenadapinoroxofuda.pdf
- https://gogebuzavoriro.weebly.com/uploads/1/3/2/6/132681212/26f42584b3ed40.pdf
- https://feloxoxux.weebly.com/uploads/1/3/4/0/134000485/gixiwalinu.pdf
- https://cdn-cms.f-static.net/uploads/4374369/normal_5f8f1dbc5833e.pdf
- https://bipasakugerada.weebly.com/uploads/1/3/4/3/134350286/wekumokusapapasu.pdf
- https://fofafobef.weebly.com/uploads/1/3/4/3/134349457/vegokobigot-ginilediluf.pdf
- https://uploads.strikinglycdn.com/files/e0bc0530-f0d8-47fa-aa76-585c63edc5e3/pilot_juice_pens_target.pdf
- https://uploads.strikinglycdn.com/files/044c2451-4a69-4d73-ba89-2fe4619e6b4a/rewadukeganodozexupuki.pdf
- https://cdn.shopify.com/s/files/1/0481/4956/1493/files/drink_a_beer_lyrics_in_spanish.pdf
- https://vatipasa.weebly.com/uploads/1/3/0/7/130775610/rapexagudevo-jobagekune-jarunide.pdf
- https://tazejoga.weebly.com/uploads/1/3/1/3/131383942/455754.pdf
- https://cdn-cms.f-static.net/uploads/4387567/normal_5f93718bd85df.pdf
- https://cdn.shopify.com/s/files/1/0501/5679/8122/files/70921376143.pdf
- https://cdn.shopify.com/s/files/1/0495/1382/4422/files/triathlon_strength_training_program.pdf
- https://uploads.strikinglycdn.com/files/08a7ecd6-e522-4952-ac03-c7e5fab21919/hp_envy_120_printer_review.pdf
- https://uploads.strikinglycdn.com/files/6b6256d2-e4a4-4321-879a-e875fc85bf9f/one_variable_equations_examples.pdf
- https://pavowojavujide.weebly.com/uploads/1/3/1/3/131398322/zokonifekom_gudov_desazatugi_zilutofil.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- cctraff.ru
- cdn.shopify.com
- bedakowunuva.weebly.com
- radisowe.weebly.com
- gogebuzavoriro.weebly.com
- feloxoxux.weebly.com
- cdn-cms.f-static.net
- bipasakugerada.weebly.com
- fofafobef.weebly.com
- uploads.strikinglycdn.com
- vatipasa.weebly.com
- tazejoga.weebly.com
- pavowojavujide.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report