SUSPICIOUS — xofotikadujukosome.pdf
SUSPICIOUS — xofotikadujukosome.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
087c4a267cbf9aac332bae289fcd694c157ad9b32ddf7ef3373d9cd7442ae9d4 - SHA-1:
0fc10e6324235f9bd21a9b2b6fa137663c369ec7 - MD5:
ef4bb284b29b0727a0260e6918a4ebd2 - ssdeep:
768:dgGzpDppEfjXEaZztT9csmIm3UkE7Fc0SHwq4hFTumVsXZa36okTrxKMWHI/0u:eGFNpEf7Eay9mFTumVspa36okXxz6lu - TLSH:
T1A1329DF34097EC8CBA8F6B1399E7109A614AC74DA13697A045C8776CC97C6FC2F14A24 - Submitted as: xofotikadujukosome.pdf
- File type: pdf · Size: 46361 bytes
- Verdict: suspicious (58/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/c726aa48700e.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=convert+url+link+to+pdf+online, https://site-1044455.mozfiles.com/files/1044455/luzokobita.pdf, https://site-1039290.mozfiles.com/files/1039290/sujevuwinajiporiwa.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=convert+url+link+to+pdf+online
- https://site-1044455.mozfiles.com/files/1044455/luzokobita.pdf
- https://site-1039290.mozfiles.com/files/1039290/sujevuwinajiporiwa.pdf
- https://site-1041782.mozfiles.com/files/1041782/free_download_book_wings_of_fire.pdf
- https://site-1042510.mozfiles.com/files/1042510/bepujudugu.pdf
- https://site-1042740.mozfiles.com/files/1042740/53908538119.pdf
- https://cdn.shopify.com/s/files/1/0502/3930/7948/files/deloitte_retail_trends_2020.pdf
- https://cdn.shopify.com/s/files/1/0427/6640/1692/files/33676794901.pdf
- https://cdn.shopify.com/s/files/1/0431/4130/0380/files/2015_ap_calc_bc_frq_5.pdf
- https://kokubexajaluk.weebly.com/uploads/1/3/2/6/132681668/c726aa48700e.pdf
- https://taxajadotediru.weebly.com/uploads/1/3/0/8/130873824/valewebofege.pdf
- https://pituluwo.weebly.com/uploads/1/3/1/4/131437949/bifoz.pdf
- https://cdn-cms.f-static.net/uploads/4366381/normal_5f874d0bc44fa.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_5f86f4b859e9a.pdf
- https://cdn-cms.f-static.net/uploads/4366319/normal_5f879d83ea2ed.pdf
- https://cdn.shopify.com/s/files/1/0500/0996/4735/files/34986646938.pdf
- https://cdn.shopify.com/s/files/1/0501/9009/0413/files/behaviorally_anchored_rating_scale_sample.pdf
- https://cdn.shopify.com/s/files/1/0433/3433/6670/files/18514423378.pdf
- https://cdn-cms.f-static.net/uploads/4368229/normal_5f88ba3ec0b63.pdf
- https://cdn-cms.f-static.net/uploads/4365594/normal_5f8817a361248.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- ggtraff.ru
- site-1044455.mozfiles.com
- site-1039290.mozfiles.com
- site-1041782.mozfiles.com
- site-1042510.mozfiles.com
- site-1042740.mozfiles.com
- cdn.shopify.com
- kokubexajaluk.weebly.com
- taxajadotediru.weebly.com
- pituluwo.weebly.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report