MALICIOUS — 9002939.pdf
MALICIOUS — 9002939.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (70/100). 2 of 53 detection engines flagged it.
Identification
- SHA-256:
ee07d74e5b0da45ecf3798b2710b3105932732cda450fd68dfbb8f37825f86a4 - SHA-1:
2b93884d46074930f0bb263ae42fdd553a5afa9b - MD5:
e06cb978255715a0f11fc83ba8dea6b4 - ssdeep:
768:JgGzpDOLHQpI3Dhi0SRHqbyCVuFCsPXdYskeuoiQN4L2Mu930MmVtDBgSxt2dy:qGFaZw9qbyZBzkendk2MU305VtDOmt2E - TLSH:
T179329EF35093DE8CBACBA717AEF62098A549DB4C6032DB604488372DC47C6ED7E505A1 - Submitted as: 9002939.pdf
- File type: pdf · Size: 44070 bytes
- Verdict: malicious (70/100)
Detections (2 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The malicious score of 70/100 is the fusion of 4 weighted signals:
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://traffnew.ru/wb?keyword=nexus%20mod%20manager%20won%20t%20download%20mods, https://cdn-cms.f-static.net/uploads/4462376/normal_5fa501457e7ab.pdf, https://uploads.strikinglycdn.com/files/4b8db2fb-9b21-4437-9145-7f89a0dabec1/31163993624.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffnew.ru/wb?keyword=nexus%20mod%20manager%20won%20t%20download%20mods
- https://cdn-cms.f-static.net/uploads/4462376/normal_5fa501457e7ab.pdf
- https://uploads.strikinglycdn.com/files/4b8db2fb-9b21-4437-9145-7f89a0dabec1/31163993624.pdf
- https://uploads.strikinglycdn.com/files/fd59f5bc-04f5-4273-bbd2-f5a6170311f2/suzufewojuku.pdf
- https://cdn-cms.f-static.net/uploads/4450884/normal_5f9e76cf6d179.pdf
- https://cdn-cms.f-static.net/uploads/4381997/normal_5f9757c326fe1.pdf
- https://nunezexivu.weebly.com/uploads/1/3/4/4/134440215/makefuvumagotu-pidoxax.pdf
- https://uploads.strikinglycdn.com/files/2eec5621-8d6a-4cad-b157-6ea63ceff32e/mevufepuruzoxaxoxuxiwa.pdf
- https://cdn-cms.f-static.net/uploads/4469359/normal_5fa6b9db193a9.pdf
- https://dodevapamoj.weebly.com/uploads/1/3/4/3/134352329/sujud.pdf
- https://s3.amazonaws.com/julaxel/nasufapap.pdf
- https://mipirizu.weebly.com/uploads/1/3/2/6/132682564/222691ae7750.pdf
- https://cdn-cms.f-static.net/uploads/4379483/normal_5f8b028c919ec.pdf
- https://duvonejubuzal.weebly.com/uploads/1/3/4/3/134321315/galazemew-kodis.pdf
- https://uploads.strikinglycdn.com/files/89197e98-7308-4093-9df1-9c6ee649e015/43050708157.pdf
- https://uploads.strikinglycdn.com/files/2d60b38b-2ebb-448a-accb-32f1fc9df454/11794654761.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffnew.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- nunezexivu.weebly.com
- dodevapamoj.weebly.com
- s3.amazonaws.com
- mipirizu.weebly.com
- duvonejubuzal.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report