SUSPICIOUS — nufafu.pdf
SUSPICIOUS — nufafu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
82550e028003396d06a7c178e3481371615c55594643aac0027546beb7a9ebe4 - SHA-1:
27166fa2d284c5c6d21b34bc432241fd6029fd81 - MD5:
a23a57cc54a71bbe21648e905d1d8056 - ssdeep:
768:vgGzpD00CtK8+Xn5763On5WRX/soRFGwZ3LPkw:YGFYM3oe5WRX/sBwZ3LPkw - TLSH:
T114318DF714D7ED8CAA876B03AEA2115A608AC7CC212793A018CC772DD4BC6BD6E41951 - Submitted as: nufafu.pdf
- File type: pdf · Size: 41132 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/9dbb3b7c-8eac-43fe-8b0e-6e066fdbe154/36265196299.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=cadkey+19+free+download, https://uploads.strikinglycdn.com/files/9dbb3b7c-8eac-43fe-8b0e-6e066fdbe154/36265196299.pdf, https://uploads.strikinglycdn.com/files/dcc7b1c6-20a5-48e5-b92c-313a781ef02e/zifimasi.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=cadkey+19+free+download
- https://uploads.strikinglycdn.com/files/9dbb3b7c-8eac-43fe-8b0e-6e066fdbe154/36265196299.pdf
- https://uploads.strikinglycdn.com/files/dcc7b1c6-20a5-48e5-b92c-313a781ef02e/zifimasi.pdf
- https://uploads.strikinglycdn.com/files/1fe23020-5468-4483-bd08-6bc0aa241986/narosilozow.pdf
- https://uploads.strikinglycdn.com/files/a72f56d7-7e1b-4dae-9989-438e224c955a/36407480637.pdf
- https://uploads.strikinglycdn.com/files/34753603-84cc-4902-aeaa-5121655a4d5a/kazisanisidela.pdf
- https://uploads.strikinglycdn.com/files/d3f72d96-7802-416d-9398-9108fa73d3cf/63632643675.pdf
- https://uploads.strikinglycdn.com/files/ee64c851-be66-4886-bc4f-d82ad2a57fd8/39084569836.pdf
- https://uploads.strikinglycdn.com/files/de76fe20-4c38-406a-8322-3f095db02209/82135781822.pdf
- https://cdn.shopify.com/s/files/1/0431/1767/4656/files/singular_possessive_nouns_worksheets_3rd_grade.pdf
- https://cdn.shopify.com/s/files/1/0479/4548/2407/files/muveloruboser.pdf
- https://cdn.shopify.com/s/files/1/0485/2200/2587/files/the_escapists_xbox_one_crafting_guide.pdf
- https://cdn.shopify.com/s/files/1/0479/2257/7564/files/bewutemamijeforolezu.pdf
- https://uploads.strikinglycdn.com/files/68ba8944-e9eb-4a48-bfb4-62d4c403a3e8/23530529171.pdf
- https://uploads.strikinglycdn.com/files/145286c9-f5a2-43cc-ade8-7bab198bd60c/malapotaj.pdf
- https://uploads.strikinglycdn.com/files/198becaa-d4d3-483e-866a-b86261317f9e/dapaves.pdf
- https://uploads.strikinglycdn.com/files/199c6850-ddf1-4a92-8b1d-84839273a942/83189407444.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report