SUSPICIOUS — nuxureb.pdf
SUSPICIOUS — nuxureb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
dbdb494671c69da58e798ffb7605497059be7d8b8a7130fc48bc3238f20cd54c - SHA-1:
6a6b5f4d9f604995a15846bb22205350ae6fbb92 - MD5:
f240c9b9d0430ca7cc92fcd8301a582a - ssdeep:
768:pgGzpDVpHsAmQvl6hD4ydt5G5CAAXu1nCQ1p/9C013FE09nu7f2zRqjjK:KGFxpzmQv2AAXuxCY/hNFJ9nu7f2zwju - TLSH:
T120328CF750DBED8C7B8BAF139EEB1158618AD78951269790448C372CC47C6EDAE00A12 - Submitted as: nuxureb.pdf
- File type: pdf · Size: 44061 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=weber%20carburetor%20manuals, https://uploads.strikinglycdn.com/files/9992513f-0f2f-41c8-af0a-894d0f516c0b/youtube_new_york_tourist_guide.pdf, https://uploads.strikinglycdn.com/files/6dc79b6b-3864-45e7-a9fd-4fbe2165f8eb/mikifexejesedajulax.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=weber%20carburetor%20manuals
- https://uploads.strikinglycdn.com/files/9992513f-0f2f-41c8-af0a-894d0f516c0b/youtube_new_york_tourist_guide.pdf
- https://uploads.strikinglycdn.com/files/6dc79b6b-3864-45e7-a9fd-4fbe2165f8eb/mikifexejesedajulax.pdf
- https://uploads.strikinglycdn.com/files/0869d27c-05ad-405f-8fa4-07ca76ee6104/xedawawifavedubin.pdf
- https://uploads.strikinglycdn.com/files/767ca97c-1690-441b-8709-3e78a499e905/41167480382.pdf
- https://uploads.strikinglycdn.com/files/33db39fe-3f5e-4cb6-9273-f3f1cd21f9c5/73376684694.pdf
- https://cdn.shopify.com/s/files/1/0431/3956/3686/files/25112695338.pdf
- https://cdn.shopify.com/s/files/1/0482/8472/9506/files/generaciones_de_los_derechos_humanos_en_guatemala.pdf
- https://cdn.shopify.com/s/files/1/0431/3029/0327/files/lixuzobijifat.pdf
- https://wojedebaroz.weebly.com/uploads/1/3/1/6/131637691/f15cfa599048c6.pdf
- https://rabifupokuwu.weebly.com/uploads/1/3/1/1/131164250/sugikubuwova-gogovulerep-mufapifuvel-rurimul.pdf
- https://vopevejefed.weebly.com/uploads/1/3/1/6/131606133/fitureji_benonudurivel_vunodekuvos_xapilirav.pdf
- https://cdn-cms.f-static.net/uploads/4368240/normal_5f89521e6045b.pdf
- https://cdn-cms.f-static.net/uploads/4372086/normal_5f8a039c9a719.pdf
- https://cdn-cms.f-static.net/uploads/4379049/normal_5f8a528bf16ad.pdf
- https://cdn-cms.f-static.net/uploads/4368487/normal_5f8a7a53ec43a.pdf
- https://uploads.strikinglycdn.com/files/dc2f8766-890c-4aac-bf1a-71d008ac801d/72164438318.pdf
- https://uploads.strikinglycdn.com/files/d24abffc-8dd8-4ead-8323-76b04fb366fa/75077491000.pdf
- https://uploads.strikinglycdn.com/files/0010450b-942e-4606-9395-4b2eab709e50/51012760523.pdf
- https://uploads.strikinglycdn.com/files/917b9dcf-6931-4f95-9dc0-573cbba13ac0/rugana.pdf
- https://uploads.strikinglycdn.com/files/4e676810-eb3a-48bb-bb32-95e036ba4079/jisanadebepebuj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- wojedebaroz.weebly.com
- rabifupokuwu.weebly.com
- vopevejefed.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report