SUSPICIOUS — nukegerefetodewi.pdf
SUSPICIOUS — nukegerefetodewi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
7c4f9d4ef54f05f54a6c17cd8ca28ac81b525197704cf0fb4b361a79500c131e - SHA-1:
53ed9cb7a069c0357ee06f9f79f1bb69d7f8e807 - MD5:
b0d4106b799269b27a4771da00ae7c54 - ssdeep:
768:KgGzpDwpu2DOi4O20rCFcS9Te6pT3M8on/SrqUXnNmlPl+2CLgJj6MXPstskmk/6:XGFkpfh4fT3/qUdbQWMXktF/mlF - TLSH:
T1C8339EF310D7EC8C7E8B9F43AD67109E7989D38960369BA104D8762CC4BC6AD6F10961 - Submitted as: nukegerefetodewi.pdf
- File type: pdf · Size: 51341 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=hp%208750%20driver, https://uploads.strikinglycdn.com/files/b0a2c6e8-a169-47aa-95a7-14806fb951c7/85354669919.pdf, https://uploads.strikinglycdn.com/files/4eaf2317-034f-4180-b800-871f3aa73d62/31643392959.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=hp%208750%20driver
- https://uploads.strikinglycdn.com/files/b0a2c6e8-a169-47aa-95a7-14806fb951c7/85354669919.pdf
- https://uploads.strikinglycdn.com/files/4eaf2317-034f-4180-b800-871f3aa73d62/31643392959.pdf
- https://uploads.strikinglycdn.com/files/51ab9421-09d3-4bdc-bf20-79eca54d9443/gumagepidof.pdf
- https://uploads.strikinglycdn.com/files/1d424132-786c-4f3b-8010-6782804344d3/51840903032.pdf
- https://uploads.strikinglycdn.com/files/9cdb6dbc-545f-4e0b-b7b6-6534936655cb/2568983006.pdf
- https://cdn.shopify.com/s/files/1/0481/7233/5255/files/como_te_amo_in_spanish.pdf
- https://cdn.shopify.com/s/files/1/0502/8508/4857/files/duxipunokufitufej.pdf
- https://cdn.shopify.com/s/files/1/0432/5477/5970/files/craigslist_kansas_city_motorcycles.pdf
- https://cdn.shopify.com/s/files/1/0497/3835/0753/files/prison_notebooks.pdf
- https://cdn.shopify.com/s/files/1/0481/5968/6823/files/vetekix.pdf
- https://cdn.shopify.com/s/files/1/0435/9074/6271/files/retropie_best_games_list.pdf
- https://fuparududewon.weebly.com/uploads/1/3/1/8/131856041/terapil.pdf
- https://sokuvotaboraj.weebly.com/uploads/1/3/0/7/130776263/ziropur.pdf
- https://raxiruzaxulam.weebly.com/uploads/1/3/0/7/130738564/xotusixagupivim-wodelajugefa.pdf
- https://kasukironumasex.weebly.com/uploads/1/3/1/4/131454791/mejewewevalek.pdf
- https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/fogovesakujog.pdf
- https://cdn-cms.f-static.net/uploads/4370073/normal_5f89426f30909.pdf
- https://cdn-cms.f-static.net/uploads/4367283/normal_5f87ab105f86b.pdf
- https://cdn-cms.f-static.net/uploads/4368736/normal_5f88191a25364.pdf
- https://cdn-cms.f-static.net/uploads/4366374/normal_5f875e9b4f174.pdf
- https://cdn-cms.f-static.net/uploads/4367311/normal_5f88ad5f71965.pdf
- https://uploads.strikinglycdn.com/files/587a4cb2-a43b-425c-8182-f03de62ed2e6/8925054960.pdf
- https://uploads.strikinglycdn.com/files/f2d7722a-7a13-4b02-8454-dbbd7b6d5ecf/18632989193.pdf
- https://uploads.strikinglycdn.com/files/fe6bef11-c8a9-48ec-98cf-3e4bec47c981/jeruwuvesa.pdf
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- fuparududewon.weebly.com
- sokuvotaboraj.weebly.com
- raxiruzaxulam.weebly.com
- kasukironumasex.weebly.com
- naxesitigas.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report