SUSPICIOUS — nanowiluwabuzojal.pdf
SUSPICIOUS — nanowiluwabuzojal.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7ad71aa76d69352544a13a41274cbe16c42abaa5c943cad25684f5469f838cb1 - SHA-1:
6ee8ff903b7550cc6cad3023ec98b554a6613b76 - MD5:
8c25a12140645fb8b8ddabf2d69af547 - ssdeep:
768:OgGzpD/ua33mxOvb8tbky2AMOib+532x6mxOeSBRy4v:rGF70t7N9iKx2kfeSBRy4v - TLSH:
T1FA31AEF75097ED9C798A6F079DEA205C614AD38D1031A3A049C8BA3CC47C6FE7E40A61 - Submitted as: nanowiluwabuzojal.pdf
- File type: pdf · Size: 42113 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/strik?keyword=6th+grade+math+pdf+worksheets, https://site-1036651.mozfiles.com/files/1036651/xonetom.pdf, https://site-1036695.mozfiles.com/files/1036695/rebenogobupimenomisotibam.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/strik?keyword=6th+grade+math+pdf+worksheets
- https://site-1036651.mozfiles.com/files/1036651/xonetom.pdf
- https://site-1036695.mozfiles.com/files/1036695/rebenogobupimenomisotibam.pdf
- https://site-1036681.mozfiles.com/files/1036681/37065286283.pdf
- https://site-1036667.mozfiles.com/files/1036667/renizesagewumususegiru.pdf
- https://site-1036764.mozfiles.com/files/1036764/3155367529.pdf
- https://site-1036945.mozfiles.com/files/1036945/xugukekugetojuxalokefe.pdf
- https://site-1037246.mozfiles.com/files/1037246/vadagobudi.pdf
- https://uploads.strikinglycdn.com/files/1c2bcb19-9b4a-4d2d-b82f-227bc56ec128/50999529191.pdf
- https://uploads.strikinglycdn.com/files/49fc60a0-fb90-43c2-bd21-eae654b6e3db/wejukidupijovuzafon.pdf
- https://uploads.strikinglycdn.com/files/9ab84271-1cd7-40d3-ade7-372fc81f06e1/fisetuloxebagada.pdf
- https://uploads.strikinglycdn.com/files/7d824df0-8eed-4ef5-8ab1-8b534d6bf35d/magelunarerajeliseg.pdf
- https://uploads.strikinglycdn.com/files/35213ab7-0b17-45aa-97a3-29927a476077/tukivosisubejagesovalofa.pdf
- https://uploads.strikinglycdn.com/files/9e3842d6-5655-4c53-881d-4a161aafe485/kijifegizutelusigobenoka.pdf
- https://uploads.strikinglycdn.com/files/f2334c2c-120d-406d-82fe-605d39d13c60/mopazuborex.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- site-1036651.mozfiles.com
- site-1036695.mozfiles.com
- site-1036681.mozfiles.com
- site-1036667.mozfiles.com
- site-1036764.mozfiles.com
- site-1036945.mozfiles.com
- site-1037246.mozfiles.com
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report