SUSPICIOUS — nuwinasireva.pdf
SUSPICIOUS — nuwinasireva.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
e8415bb82ff07c45372943fc8c776050d2b638f14a5b027c1d3f20115d776507 - SHA-1:
d53339c7824ff9f75b3e43866be9d3d2e203b034 - MD5:
f32240637ffdec3dffcca48bd2094098 - ssdeep:
1536:5GFaFkE50gBDu31+FLUgubKhloJFByP3DOHxor2LbNeRm9ibubQmKKrA:MFaFkHZsojbKMyP3DOq6LbYRma8qn - TLSH:
T12C39E0F301A7FD4E768BAB136DB71065620AE7CC9237AA905448232DC0786FD3F10692 - Submitted as: nuwinasireva.pdf
- File type: pdf · Size: 91881 bytes
- Verdict: suspicious (44/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=sonic+archie+comics+pdf, https://uploads.strikinglycdn.com/files/190f554a-a2c8-4c65-af3c-9276a86c6392/3516348559.pdf, https://uploads.strikinglycdn.com/files/ee785420-5f7d-40c0-a7f9-ade6c4d4e2f2/29133930346.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ggtraff.ru/strik?keyword=sonic+archie+comics+pdf
- https://uploads.strikinglycdn.com/files/190f554a-a2c8-4c65-af3c-9276a86c6392/3516348559.pdf
- https://uploads.strikinglycdn.com/files/ee785420-5f7d-40c0-a7f9-ade6c4d4e2f2/29133930346.pdf
- https://uploads.strikinglycdn.com/files/871c671f-f6e6-4210-913d-b2406878698e/xuvomexakegiduzuwo.pdf
- https://cdn.shopify.com/s/files/1/0483/9620/6231/files/colorado_mountain_range_pictures.pdf
- https://cdn.shopify.com/s/files/1/0432/1797/7504/files/nabard_model_bankable_project_report.pdf
- https://cdn.shopify.com/s/files/1/0435/3156/7256/files/computer_admission_form_format.pdf
- https://cdn.shopify.com/s/files/1/0429/1880/5657/files/watch_player_one_online_free.pdf
- https://uploads.strikinglycdn.com/files/bf162227-32c3-4999-93a6-320cc01c93e4/99532623744.pdf
- https://uploads.strikinglycdn.com/files/26bb4bc4-e913-423b-8bbb-7af368eaa367/24991884668.pdf
- https://uploads.strikinglycdn.com/files/dd658c74-3662-4c8a-ab10-c7e0fed5682d/suwudol.pdf
- https://uploads.strikinglycdn.com/files/1874cddc-3de3-46cb-8e37-d3538b31ffd4/zuloriledaveluwuzo.pdf
- https://cdn.shopify.com/s/files/1/0430/5331/8306/files/fizafinisibinegemiwe.pdf
- https://cdn.shopify.com/s/files/1/0438/1681/2706/files/libiz.pdf
- https://cdn.shopify.com/s/files/1/0428/3065/9750/files/nba_live_mobile_apk_latest_version.pdf
- https://cdn.shopify.com/s/files/1/0430/6393/5129/files/lokafejoxujiguv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- uploads.strikinglycdn.com
- cdn.shopify.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report