SUSPICIOUS — nudag.pdf
SUSPICIOUS — nudag.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
741aaccce5954270b61910dcfd009afb7eaf1cf406d248ff29992bcbcd9bd8ed - SHA-1:
171ca9af1d586c7a4d852b631e144a6c9983f570 - MD5:
af520259c89059fc6880df3fb4d0fdd8 - ssdeep:
768:HgGzpDep0xbTc210fjMRhmhZjApZdwhdOzVDwIjZxKnubFtdK1kxoPmgw0:AGFipyCd8VUI9wuBwLy0 - TLSH:
T13C327DF350A7ED8C7A8EAF07AEAB155D4149C3883027D7A05598336CD4BC6FD6E01A60 - Submitted as: nudag.pdf
- File type: pdf · Size: 44411 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/7fb657ba-f3a8-4f96-aee0-b84539d08780/gelulofu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=2006+vw+touareg+owners+manual, https://cdn.shopify.com/s/files/1/0485/9972/8293/files/bostitch_nail_gun_sb-1664fn_manual.pdf, https://cdn.shopify.com/s/files/1/0486/1716/0862/files/mad_murderer_knife_code.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://cctraff.ru/strik?keyword=2006+vw+touareg+owners+manual
- https://cdn.shopify.com/s/files/1/0485/9972/8293/files/bostitch_nail_gun_sb-1664fn_manual.pdf
- https://cdn.shopify.com/s/files/1/0486/1716/0862/files/mad_murderer_knife_code.pdf
- https://cdn.shopify.com/s/files/1/0429/5806/1724/files/50847861552.pdf
- https://cdn.shopify.com/s/files/1/0437/1634/6007/files/best_free_jigsaw_puzzles_for_android.pdf
- https://cdn.shopify.com/s/files/1/0433/6241/8847/files/38999240548.pdf
- https://cdn.shopify.com/s/files/1/0434/0314/9479/files/ipsec_vpn_configuration_guide.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/us_constitution_2nd_amendment.pdf
- https://cdn.shopify.com/s/files/1/0500/5079/3643/files/pejorezudesofafizep.pdf
- https://cdn-cms.f-static.net/uploads/4365606/normal_5f8916995c292.pdf
- https://cdn-cms.f-static.net/uploads/4391920/normal_5f8e885a448b2.pdf
- https://cdn-cms.f-static.net/uploads/4381748/normal_5f8cc1ba436e4.pdf
- https://uploads.strikinglycdn.com/files/5f79901c-3544-4a3b-8636-5f578742b2f3/29883482587.pdf
- https://uploads.strikinglycdn.com/files/7fb657ba-f3a8-4f96-aee0-b84539d08780/gelulofu.pdf
- https://uploads.strikinglycdn.com/files/4aac0be0-9e2d-4f5d-a111-574ec2a8818a/dipudev.pdf
- https://uploads.strikinglycdn.com/files/b07f16db-29b6-4a5f-9866-c875b69fe13b/73227070613.pdf
- https://uploads.strikinglycdn.com/files/94de4565-1db1-4e09-9843-f3006268a4d1/digaves.pdf
- https://uploads.strikinglycdn.com/files/2004979f-1a8d-4a82-95f7-4d032cced8c5/30013503465.pdf
- https://uploads.strikinglycdn.com/files/b4570084-6fc1-4d69-a776-b28482b5541e/bejezixubedotofugasux.pdf
- https://uploads.strikinglycdn.com/files/a8061a00-ff2f-47a2-8bb0-7559070dff29/sakobefopobebove.pdf
- https://s3.amazonaws.com/memul/nuxelun.pdf
- https://s3.amazonaws.com/felasorarabipis/22831358181.pdf
- https://s3.amazonaws.com/zirojopemup/nanusakumatumek.pdf
- https://s3.amazonaws.com/mijedusovineti/56960983394.pdf
- https://s3.amazonaws.com/henghuili-files/76938427550.pdf
Embedded domains
- cctraff.ru
- cdn.shopify.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report